Sploitus

CVE-2014-3514

No indexed exploits for CVE-2014-3514 yet

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.

Affected products
Ruby On Rails
Rubyonrails Rails
= 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7, 4.0.8, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.4
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
2.8% (85th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2014-08-20
CVE-2014-3514 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2014-3514 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2014-3514 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.