RubySec

Providing security resources for the Ruby community

OSVDB-96396 (activemodel): Don't allow confirmation to pass if confirmation value is nil and doesn't match value.

Don't allow confirmation to pass if confirmation value is nil and doesn't match value.

Published: May 11, 2012

SECURITY IDENTIFIERS

GEM

activemodel

FRAMEWORK

Ruby on Rails

PATCHED VERSIONS

None available.

DESCRIPTION

Don't allow confirmation to pass if confirmation value is nil and doesn't match value.

RELATED