CVE-2014-3514: Strong Parameter bypass with create_with
(updated )
The create_with
functionality in Active Record was implemented incorrectly and completely bypasses the strong parameter protection.
References
Detect and mitigate CVE-2014-3514 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →