mirror of
https://github.com/rails/rails.git
synced 2022-11-09 12:12:34 -05:00
306dc1a499
If the request parameters are passed to create_with and where they can be used to do mass assignment when used in combination with Relation#create. Fixes CVE-2014-3514 Conflicts: activerecord/lib/active_record/relation/query_methods.rb |
||
---|---|---|
.. | ||
active_model | ||
active_model.rb |