CVE-2010-3933

Description

Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.712

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2010-3933 are fixed in Ruby-activerecord 2.3.10Windows
Vulnerabilities CVE-2010-3933 are fixed in Ruby-activerecord 3.0.1Windows
Vulnerabilities CVE-2010-3933 are fixed in Ruby-activerecord for Linux 2.3.10Linux
Vulnerabilities CVE-2010-3933 are fixed in Ruby-activerecord for Linux 3.0.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234