Ruby on Rails 'create _ with () 'Function Security Restriction Bypass Vulnerability
Release date:
Updated on:
Affected Systems:
Ruby on Rails
Description:
Bugtraq id: 69265
CVE (CAN) ID: CVE-2014-3514
Ruby on Rails (RoR or Rails) is an open-source Web application framework written in Ruby. It is developed in strict accordance with the MVC structure.
Ruby on Rails has a Security Restriction Bypass Vulnerability in the implementation of the create_with () function. Attackers can exploit this vulnerability to bypass certain security restrictions and obtain application access permissions.
<* Source: Stephen Touset
*>
Suggestion:
Vendor patch:
Ruby on Rails
-------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.rubyonrails.com/
This article permanently updates the link address: