Vulnerability index

Browse CVEs

110 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Actionpack MEDIUM 6.1
CVE-2022-27777

A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into spe…

Fix: 5.2.7.1 / 6.0.4.8+
Fix from $1,600 2022-05-26
Rails MEDIUM 5.9
CVE-2022-23633

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event …

Fix: 5.2.6.2 / 6.0.4.6+
Fix from $1,600 2022-02-11
Rails MEDIUM 6.1
CVE-2021-44528

A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with c…

Patch available
Fix from $1,600 2022-01-10
Rails MEDIUM 6.1
CVE-2011-1497

A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6.

Fix: 3.0.6+
Fix from $1,600 2021-10-19
Rails MEDIUM 6.1
CVE-2021-22942

A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a…

Fix: 6.0.4.1 / 6.1.4.1+
Fix from $1,600 2021-10-18
Rails HIGH 7.5
CVE-2021-22902

The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of …

Fix: 6.0.3.7 / 6.1.0.2+
Fix from $1,950 2021-06-11
Rails HIGH 7.5
CVE-2021-22904

The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication l…

Fix: 5.2.4.6 / 5.2.6+
Fix from $1,950 2021-06-11
Rails MEDIUM 6.1
CVE-2021-22903

The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certai…

Fix: 6.1.3.2+
Fix from $1,600 2021-06-11
Rails HIGH 7.5
CVE-2021-22885

A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_ur…

Fix: 5.2.4.6 / 6.0.3.7+
Fix from $1,950 2021-05-27
Active Record Session Store MEDIUM 5.3
CVE-2019-25025

The activerecord-session_store (aka Active Record Session Store) component through 1.1.3 for Ruby on Rails does not use a constant-time approach when…

Fix: after 1.1.3
Fix from $1,600 2021-03-05
Rails HIGH 7.5
CVE-2021-22880

The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. C…

Fix: 5.2.4.5 / 6.0.3.5+
Fix from $1,950 2021-02-11
Rails MEDIUM 6.1
CVE-2021-22881EPSS 87%

The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` header…

Fix: 6.0.3.5 / 6.1.2.1+
Fix from $1,600 2021-02-11
Rails MEDIUM 6.1
CVE-2020-8264EPSS 67%

In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or em…

Fix: 6.0.3.4+
Fix from $1,600 2021-01-06
Rails HIGH 8.8
CVE-2020-8163EPSS 82%

The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `rend…

Fix: 5.0.1+
Fix from $1,950 2020-07-02
Rails MEDIUM 6.5
CVE-2020-8185

A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in pro…

Fix: 6.0.3.2+
Fix from $1,600 2020-07-02
Rails CRITICAL 9.8
CVE-2020-8165EPSS 46%

A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided…

Fix: 5.2.4.3 / 6.0.3.1+
Fix from $2,300 2020-06-19
Rails MEDIUM 6.5
CVE-2020-8167

A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.

Fix: 5.2.4.3 / 6.0.3.1+
Fix from $1,600 2020-06-19
Rails HIGH 7.5
CVE-2020-8162

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows …

Fix: 5.2.4.2 / 6.0.3.1+
Fix from $1,950 2020-06-19
Rails HIGH 7.5
CVE-2020-8164

A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be…

Fix: 5.2.4.3 / 6.0.3.1+
Fix from $1,950 2020-06-19
Actionpack Page Caching CRITICAL 9.8
CVE-2020-8159EPSS 5%

There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially result…

Fix: 1.2.1+
Fix from $2,300 2020-05-12
Active Resource HIGH 7.5
CVE-2020-8151

There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to acce…

Fix: 5.1.1+
Fix from $1,950 2020-05-12
Rails MEDIUM 6.5
CVE-2010-3299

The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.

No fix yet
Fix from $1,600 2019-11-12
Rails CRITICAL 9.8
CVE-2019-5420EPSS 92%

A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated dev…

Fix: 5.2.2.1+
Fix from $2,300 2019-03-27
Rails HIGH 7.5
CVE-2019-5418 KEVEPSS 99%

There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers…

Fix: 4.2.11.1 / 5.0.7.2+
Fix from $1,950 2019-03-27
Rails HIGH 7.5
CVE-2019-5419EPSS 9%

There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept hea…

Fix: 4.2.11.1 / 5.0.7.2+
Fix from $1,950 2019-03-27
Rails HIGH 7.5
CVE-2018-16476

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserializ…

Fix: 4.2.11 / 5.0.7.1+
Fix from $1,950 2018-11-30
Rails MEDIUM 6.5
CVE-2018-16477

A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify the `content-disposition` an…

Fix: 5.2.1.1+
Fix from $1,600 2018-11-30
Html Sanitizer MEDIUM 6.1
CVE-2018-3741

There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be …

Fix: after 1.0.3
Fix from $1,600 2018-03-30
Rails HIGH 8.1
CVE-2017-17916

SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via …

Fix: after 5.1.4
Fix from $1,950 2017-12-29
Rails HIGH 8.1
CVE-2017-17917

SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via th…

Fix: after 5.1.4
Fix from $1,950 2017-12-29