Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.
References
Link | Resource |
---|---|
http://www.vupen.com/english/advisories/2010/2719 | Vendor Advisory |
http://weblog.rubyonrails.org/2010/10/15/security-vulnerability-in-nested-attributes-code-in-ruby-on-rails-2-3-9-and-3-0-0 | Vendor Advisory |
http://securitytracker.com/id?1024624 | |
http://secunia.com/advisories/41930 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-10-27 17:00
Updated : 2019-08-08 07:49
NVD link : CVE-2010-3933
Mitre link : CVE-2010-3933
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
rubyonrails
- rails