Vulnerability identifier: #VU8580
Vulnerability risk: Low
CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-264
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Ruby on Rails
Universal components / Libraries /
Scripting languages
Vendor: Rails
Description
The vulnerability allows a remote attacker to bypass certain security restrictions.
activerecord/lib/active_record/nested_attributes.rb in Active Record in
Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before
4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not
properly implement a certain destroy option, which allows remote
attackers to bypass intended change restrictions by leveraging use of
the nested attributes feature.
Mitigation
Update to version 3.2.22.1, 4.1.14.1 or 4.2.5.1.
Vulnerable software versions
Ruby on Rails: 4.2.0 - 4.2.5 rc2, 4.1.0 - 4.1.14 rc2, 4.0.0 - 4.0.13 rc1, 3.2.0 - 3.2.22, 3.1.0 - 3.1.12
External links
http:
Rails 3.2.22.1
Rails 4.1.14.1
Rails 4.2.5.1
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.