VDB
Sign up
MEDIUM5.3

GHSA-xrr6-3pc4-m447

Active Record Improper Access Control

Quick fix

GHSA-xrr6-3pc4-m447 — activerecord: upgrade to the fixed version with the command below.

bundle update activerecord

Details

`activerecord/lib/active_record/nested_attributes.rb` in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/activerecord
Introduced in: 3.1.0Fixed in: 3.2.22.1
Fixbundle update activerecord
RubyGems/activerecord
Introduced in: 4.0.0Fixed in: 4.1.14.1
Fixbundle update activerecord
RubyGems/activerecord
Introduced in: 4.2.0Fixed in: 4.2.5.1
Fixbundle update activerecord
RubyGems/activerecord
Introduced in: 5.0.0.beta1Fixed in: 5.0.0.beta1.1
Fixbundle update activerecord

References