Oval Definition:oval:com.ubuntu.trusty:def:20143514000
Revision Date:2014-08-20Version:1
Title:CVE-2014-3514 on Ubuntu 14.04 LTS (trusty) - medium.
Description:activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-3514
Platform(s):Ubuntu 14.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 14.04 LTS (trusty) is installed.
  • AND Package Information
  • NOT While related to the CVE in some way, the 'rails' package in trusty is not affected (note: 'contains no code').
  • OR NOT While related to the CVE in some way, the 'rails-4.0' package in trusty is not affected.
  • OR NOT While related to the CVE in some way, the 'ruby-actionpack-3.2' package in trusty is not affected.
  • OR NOT While related to the CVE in some way, the 'ruby-activerecord-3.2' package in trusty is not affected.
  • OR NOT While related to the CVE in some way, the 'ruby-activesupport-3.2' package in trusty is not affected.
  • OR NOT While related to the CVE in some way, the 'ruby-rails-3.2' package in trusty is not affected.
  • BACK