Description
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2017-10347 Vulnerability (CVE-2017-10347)
Podcast Generator Server-Side Request Forgery (SSRF) Vulnerability (CVE-2023-53899)
Jboss EAP Improper Handling of Exceptional Conditions Vulnerability (CVE-2018-8039)
WordPress Plugin User Submitted Posts Arbitrary File Upload (20190426)
WordPress Plugin Gallery Plugin for WordPress-Envira Photo Gallery Cross-Site Scripting (1.8.3.2)