CVE-2013-0276: Rubyonrails Rails
Medium severity, CVSS 4.3. EPSS: 2.5% chance of exploitation in the next 30 days.
ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.
Affected products
- Rubyonrails Rails: version 3.2.0 only; version 3.2.1 only; version 3.2.2 only; version 3.2.3 only; version 3.2.4 only; version 3.2.5 only; …
Published 2013-02-13. Last modified 2026-06-16.