Duplicate Advisory: Moderate severity vulnerability that affects activemodel
Moderate severity
GitHub Reviewed
Published
Sep 17, 2018
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Withdrawn
This advisory was withdrawn on Jun 17, 2020
Package
Affected versions
>= 4.1.0, <= 4.1.14.0
>= 4.2, <= 4.2.5.0
Patched versions
4.1.14.1
4.2.5.1
Description
Published to the GitHub Advisory Database
Sep 17, 2018
Reviewed
Jun 17, 2020
Withdrawn
Jun 17, 2020
Last updated
Jan 31, 2023
Duplicate advisory
This advisory has been withdrawn because it is a duplicate of GHSA-543v-gj2c-r3ch. This link is maintained to preserve external references.
Original Description
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
References