CVE-2014-3514
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
- Affected products
- Ruby On Rails
- Rubyonrails Rails
- = 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7, 4.0.8, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.4
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 2.8% (85th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2014-08-20
CVE-2014-3514 at NVD
No indexed exploits for CVE-2014-3514 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2014-3514 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.