CVE-2014-3514
Last modified
CVE-2014-3514 is a vulnerability of currently unknown severity. activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.. EPSS estimates a 2.80% chance of exploitation in the next 30 days.
Description
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rubyonrails | Rails | 4.0.0 |
| Rubyonrails | Rails | 4.0.1 |
| Rubyonrails | Rails | 4.0.2 |
| Rubyonrails | Rails | 4.0.3 |
| Rubyonrails | Rails | 4.0.4 |
| Rubyonrails | Rails | 4.0.5 |
| Rubyonrails | Rails | 4.0.6 |
| Rubyonrails | Rails | 4.0.7 |
| Rubyonrails | Rails | 4.0.8 |
| Rubyonrails | Rails | 4.1.0 |
| Rubyonrails | Rails | 4.1.1 |
| Rubyonrails | Rails | 4.1.2 |
| Rubyonrails | Rails | 4.1.3 |
| Rubyonrails | Rails | 4.1.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3514?
How severe is CVE-2014-3514?
How do I fix CVE-2014-3514?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-3508The OBJ_obj2txt function in crypto/objects/obj_dat.c in Open…
- CVE-2014-3509Race condition in the ssl_parse_serverhello_tlsext function …
- CVE-2014-3510The ssl3_send_client_key_exchange function in s3_clnt.c in O…
- CVE-2014-3511The ssl23_get_client_hello function in s23_srvr.c in OpenSSL…
- CVE-2014-3512Multiple buffer overflows in crypto/srp/srp_lib.c in the SRP…
- CVE-2014-3513Memory leak in d1_srtp.c in the DTLS SRTP extension in OpenS…
- CVE-2014-3515The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.…
- CVE-2014-3516Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-3517api/metadata/handler.py in OpenStack Compute (Nova) before 2…
- CVE-2014-3518jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss…
- CVE-2014-3519The open_by_handle_at function in vzkernel before 042stab090…
- CVE-2014-3520OpenStack Identity (Keystone) before 2013.2.4, 2014.x before…
Are you affected by CVE-2014-3514?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
