From 4b084e6a3cba0f7e12e302a92d86f163c1b5b3c9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 14 Mar 2023 22:24:14 +0000 Subject: [PATCH] Publish GHSA-9rf5-jm6f-2fmm --- .../GHSA-9rf5-jm6f-2fmm/GHSA-9rf5-jm6f-2fmm.json | 16 ++-------------- 1 file changed, 2 insertions(+), 14 deletions(-) diff --git a/advisories/github-reviewed/2017/10/GHSA-9rf5-jm6f-2fmm/GHSA-9rf5-jm6f-2fmm.json b/advisories/github-reviewed/2017/10/GHSA-9rf5-jm6f-2fmm/GHSA-9rf5-jm6f-2fmm.json index 6c1af452111..631cb77dcde 100644 --- a/advisories/github-reviewed/2017/10/GHSA-9rf5-jm6f-2fmm/GHSA-9rf5-jm6f-2fmm.json +++ b/advisories/github-reviewed/2017/10/GHSA-9rf5-jm6f-2fmm/GHSA-9rf5-jm6f-2fmm.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9rf5-jm6f-2fmm", - "modified": "2020-06-16T21:29:34Z", + "modified": "2023-03-14T22:23:08Z", "published": "2017-10-24T18:33:36Z", "aliases": [ "CVE-2014-3514" ], - "summary": "High severity vulnerability that affects activerecord", + "summary": "Active Record subject to strong parameters protection bypass", "details": "activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.", "severity": [ @@ -56,14 +56,6 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-3514" }, - { - "type": "ADVISORY", - "url": "https://github.com/advisories/GHSA-9rf5-jm6f-2fmm" - }, - { - "type": "WEB", - "url": "https://groups.google.com/forum/message/raw?msg=rubyonrails-security/M4chq5Sb540/CC1Fh0Y_NWwJ" - }, { "type": "WEB", "url": "http://openwall.com/lists/oss-security/2014/08/18/10" @@ -71,10 +63,6 @@ { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2014-1102.html" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/60347" } ], "database_specific": {