VulnerabilityModified
CVE-2010-3933
Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.
MEDIUM 6.4EPSS 2.21%
Does this matter?
Lower severity and a low EPSS score (2.21%). Track it; it rarely justifies an emergency change on its own.
Description
Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 2.21% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- rubyonrails/rails
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/41930Vendor Advisory
- http://securitytracker.com/id?1024624
- http://weblog.rubyonrails.org/2010/10/15/security-vulnerability-in-nested-attributes-code-in-ruby-on-rails-2-3-9-and-3-0-0Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2719Vendor Advisory
- http://secunia.com/advisories/41930Vendor Advisory
- http://securitytracker.com/id?1024624
- http://weblog.rubyonrails.org/2010/10/15/security-vulnerability-in-nested-attributes-code-in-ruby-on-rails-2-3-9-and-3-0-0Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2719Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.