4.3
CVSSv2

CVE-2013-0276

Published: 13/02/2013 Updated: 08/08/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

ActiveRecord in Ruby on Rails prior to 2.3.17, 3.1.x prior to 3.1.11, and 3.2.x prior to 3.2.12 allows remote malicious users to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.

Vulnerable Product Search on Vulmon Subscribe to Product

rubyonrails rails 3.2.7

rubyonrails rails 3.2.9

rubyonrails rails 3.2.3

rubyonrails rails 3.2.11

rubyonrails rails 3.2.8

rubyonrails rails 3.2.4

rubyonrails rails 3.2.6

rubyonrails rails 3.2.5

rubyonrails rails 3.2.0

rubyonrails rails 3.2.1

rubyonrails rails 3.2.2

rubyonrails rails 3.2.10

rubyonrails rails 3.1.0

rubyonrails rails 3.1.3

rubyonrails rails 3.1.1

rubyonrails rails 3.1.4

rubyonrails rails 3.1.5

rubyonrails rails 3.1.2

rubyonrails rails 3.1.6

rubyonrails rails 3.1.9

rubyonrails rails 3.1.8

rubyonrails rails 3.1.7

rubyonrails rails 3.1.10

rubyonrails rails 2.3.9

rubyonrails rails 2.3.4

rubyonrails rails 2.3.1

rubyonrails rails 2.3.3

rubyonrails rails 2.3.2

rubyonrails rails 2.3.15

rubyonrails rails 2.3.0

rubyonrails rails 2.3.14

rubyonrails rails 2.3.13

rubyonrails rails 2.3.10

rubyonrails rails 2.3.16

rubyonrails rails 2.3.11

rubyonrails rails 2.3.12

Vendor Advisories

Synopsis Moderate: Subscription Asset Manager 121 update Type/Severity Security Advisory: Moderate Topic Red Hat Subscription Asset Manager 121, which fixes several securityissues, multiple bugs, and adds various enhancements, is now availableThe Red Hat Security Response Team has rated this update as ...
Synopsis Moderate: Red Hat OpenShift Enterprise 111 update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Enterprise 111 is now availableThe Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability Scoring System (CVSS) base scores, ...
Two vulnerabilities were discovered in Ruby on Rails, a Ruby framework for web application development CVE-2013-0276 The blacklist provided by the attr_protected method could be bypassed with crafted requests, having an application-specific impact CVE-2013-0277 In some applications, the +serialize+ helper in ActiveRecord could be tricked in ...

Github Repositories

Secure Rails with Hakiri Hakiri Toolbelt is a command line interface for the Hakiri platform It allows Ruby on Rails developers to automate version scraping of Ruby gems, servers, databases and other technologies used in their stacks For each technology Hakiri shows CVE vulnerabilities Here is a snippet of how it works: $ hakiri system:scan -----> Scanning system fo

Secure Ruby apps with Hakiri

Secure Rails with Hakiri Hakiri Toolbelt is a command line interface for the Hakiri platform It allows Ruby on Rails developers to automate version scraping of Ruby gems, servers, databases and other technologies used in their stacks For each technology Hakiri shows CVE vulnerabilities Here is a snippet of how it works: $ hakiri system:scan -----> Scanning system fo

Secure Rails with Hakiri

Secure Rails with Hakiri Hakiri is a command line interface (CLI) for the Hakiri platform It allows Ruby on Rails developers to automate version scraping of servers, databases and other technologies used in their stacks For each technology Hakiri shows CVE vulnerabilities Here is a snippet of how it works: $ hakiri system:scan -----> Scanning system for software versi