CVE-2010-3933
Publication date 28 October 2010
Last updated 24 July 2024
Ubuntu priority
Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.
Status
Package | Ubuntu Release | Status |
---|---|---|
rails | 10.10 maverick |
Not affected
|
10.04 LTS lucid |
Not affected
|
|
9.10 karmic |
Not affected
|
|
8.04 LTS hardy |
Not affected
|
|
6.06 LTS dapper |
Not affected
|