U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2014-7829

Change History

Initial CVE Analysis 11/19/2014 10:39:00 AM

Action Type Old Value New Value
Added CVSS V2

								
							
							
						
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Added CWE

								
							
							
						
CWE-22
Added CPE Configuration

								
							
							
						
Configuration 1
     OR
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:beta:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:beta2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:beta3:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:beta4:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:rc:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.1:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.1:pre:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.10:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.10:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.11:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.12:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.12:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.13:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.13:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.14:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.16:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.17:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.18:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.19:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.2:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.2:pre:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.20:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.3:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.4:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.4:rc:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.4:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.5:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.5:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.6:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.6:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.6:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.7:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.7:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.7:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:rc3:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:rc4:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc3:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc4:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc5:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:beta1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc3:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc4:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc5:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc6:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc7:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc8:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.1:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.1:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.1:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.1:rc3:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.10:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.2:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.2:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.2:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.3:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.4:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.4:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.5:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.5:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.6:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.7:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.8:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.9:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.0:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.0:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.0:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.1:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.10:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.11:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.12:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.13:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.13:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.15:rc3:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.16:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.17:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.18:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.19:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.20:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.2:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.2:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.3:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.3:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.3:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.4:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.4:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.5:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.6:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.7:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.8:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.0:-:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.0:beta:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.0:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.0:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.1:-:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.1:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.1:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.1:rc3:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.1:rc4:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.10:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.2:-:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.3:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.4:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.5:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.6:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.6:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.6:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.6:rc3:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.7:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.8:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.9:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.10:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.11:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.0:-:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.0:beta1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.1:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.2:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.2:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.2:rc2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.2:rc3:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.3:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.4:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.5:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.6:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.6:rc1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.7:*:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.2.0:beta1:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.2.0:beta2:*:*:*:*:*:*
          *cpe:2.3:a:rubyonrails:ruby_on_rails:4.2.0:beta3:*:*:*:*:*:*
Changed Reference Type
https://groups.google.com/forum/message/raw?msg=rubyonrails-security/rMTQy4oRCGk/loS_CRS8mNEJ No Types Assigned
https://groups.google.com/forum/message/raw?msg=rubyonrails-security/rMTQy4oRCGk/loS_CRS8mNEJ Exploit