VDB
Sign up
MEDIUM

GHSA-gjxw-5w2q-7grf

Rails activerecord gem has Improper Input Validation vulnerability

Quick fix

GHSA-gjxw-5w2q-7grf — activerecord: upgrade to the fixed version with the command below.

bundle update activerecord

Details

Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/activerecord
Introduced in: 2.3.9Fixed in: 2.3.10
Fixbundle update activerecord
RubyGems/activerecord
Introduced in: 3.0.0Fixed in: 3.0.1
Fixbundle update activerecord

References