Upstream information

CVE-2016-0753 at MITRE

Description

Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.

SUSE information

CVSS v2 Scores
  National Vulnerability Database SUSE
Base Score 4.96 4.30
Vector AV:N/AC:L/Au:N/C:N/I:P/A:N AV:N/AC:M/Au:N/C:N/I:P/A:N
Access Vector Network Network
Access Complexity Low Medium
Authentication None None
Confidentiality Impact None None
Integrity Impact Partial Partial
Availability Impact None None
CVSS v3 Scores
  National Vulnerability Database
Base Score 5.3
Vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Access Vector Network
Access Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact Low
Availability Impact None

This issue is currently rated as having moderate severity.

SUSE Bugzilla entry: 963334 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Enterprise Storage 2.1
  • ruby2.1-rubygem-activemodel-4_2 >= 4.2.2-5.1
  • ruby2.1-rubygem-activerecord-4_2 >= 4.2.2-5.1
  • ruby2.1-rubygem-activesupport-4_2 >= 4.2.2-6.1
  • rubygem-activemodel-4_2 >= 4.2.2-5.1
  • rubygem-activerecord-4_2 >= 4.2.2-5.1
  • rubygem-activesupport-4_2 >= 4.2.2-6.1
Patchnames:
SUSE-Storage-2.1-2016-247
SUSE-Storage-2.1-2016-250
SUSE-Storage-2.1-2016-261
SUSE Linux Enterprise Module for Containers 12
  • portus >= 2.0.3-2.4
Patchnames:
SUSE-SLE-Module-Containers-12-2016-672
SUSE OpenStack Cloud 5
  • ruby2.1-rubygem-activemodel-4_1 >= 4.1.9-9.1
  • ruby2.1-rubygem-activerecord-4_1 >= 4.1.9-9.1
  • ruby2.1-rubygem-activesupport-4_1 >= 4.1.9-12.1
  • rubygem-activemodel-4_1 >= 4.1.9-9.1
  • rubygem-activerecord-4_1 >= 4.1.9-9.1
  • rubygem-activesupport-4_1 >= 4.1.9-12.1
Patchnames:
sleclo50sp3-rubygem-activemodel-4_1-12422
sleclo50sp3-rubygem-activerecord-4_1-12423
sleclo50sp3-rubygem-activesupport-4_1-12424
SUSE OpenStack Cloud 6
  • ruby2.1-rubygem-activemodel-4_2 >= 4.2.2-5.1
  • ruby2.1-rubygem-activerecord-4_2 >= 4.2.2-5.1
  • ruby2.1-rubygem-activesupport-4_2 >= 4.2.2-6.1
Patchnames:
SUSE OpenStack Cloud 6 GA ruby2.1-rubygem-activemodel-4_2
SUSE OpenStack Cloud 6 GA ruby2.1-rubygem-activerecord-4_2
SUSE OpenStack Cloud 6 GA ruby2.1-rubygem-activesupport-4_2
openSUSE Leap 42.1
  • ruby2.1-rubygem-actionpack-4_2 >= 4.2.4-6.1
  • ruby2.1-rubygem-actionpack-doc-4_2 >= 4.2.4-6.1
  • ruby2.1-rubygem-actionview-4_2 >= 4.2.4-6.1
  • ruby2.1-rubygem-actionview-doc-4_2 >= 4.2.4-6.1
  • ruby2.1-rubygem-activemodel-4_2 >= 4.2.4-6.1
  • ruby2.1-rubygem-activemodel-doc-4_2 >= 4.2.4-6.1
  • ruby2.1-rubygem-activerecord-4_2 >= 4.2.4-6.1
  • ruby2.1-rubygem-activerecord-doc-4_2 >= 4.2.4-6.1
  • ruby2.1-rubygem-activesupport-4_2 >= 4.2.4-6.1
  • ruby2.1-rubygem-activesupport-doc-4_2 >= 4.2.4-6.1
  • rubygem-actionpack-4_2 >= 4.2.4-6.1
  • rubygem-actionview-4_2 >= 4.2.4-6.1
  • rubygem-activemodel-4_2 >= 4.2.4-6.1
  • rubygem-activerecord-4_2 >= 4.2.4-6.1
  • rubygem-activesupport-4_2 >= 4.2.4-6.1
Patchnames:
openSUSE-2016-159


List of planned updates

The following information is the current evaluation information for this security issue. It might neither be accurate nor complete, Use at own risk.
Product(s) Source package
  • SUSE Linux Enterprise SDK 11 SP2
rubygem-activesupport-3_2