MEDIUM5.3
GHSA-xrr6-3pc4-m447
Active Record Improper Access Control
Quick fix
GHSA-xrr6-3pc4-m447 — activerecord: upgrade to the fixed version with the command below.
bundle update activerecordDetails
`activerecord/lib/active_record/nested_attributes.rb` in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-7577[ADVISORY]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activerecord/CVE-2015-7577.yml[WEB]
- https://groups.google.com/forum/#!topic/rubyonrails-security/cawsWcQ6c8g[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178041.html[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178065.html[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.html[WEB]
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00034.html[WEB]
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00043.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2016-0296.html[WEB]
- http://www.debian.org/security/2016/dsa-3464[WEB]
- http://www.openwall.com/lists/oss-security/2016/01/25/10[WEB]