18F/e-manifest

View on GitHub

Showing 761 of 761 total issues

Keepalive thread overload/DoS in puma
Open

puma (2.15.3)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Denial of Service Vulnerability in ActiveRecord’s PostgreSQL adapter
Open

activerecord (4.2.5.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

json Gem for Ruby Unsafe Object Creation Vulnerability (additional fix)
Open

json (1.8.3)
Severity: Critical
Found in Gemfile.lock by bundler-audit

ReDoS based DoS vulnerability in Active Support’s underscore
Open

activesupport (4.2.5.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

HTTP Smuggling via Transfer-Encoding Header in Puma
Open

puma (2.15.3)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Possible shell escape sequence injection vulnerability in Rack
Open

rack (1.6.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Keepalive Connections Causing Denial Of Service in puma
Open

puma (2.15.3)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in puma
Open

puma (2.15.3)
Severity: Info
Found in Gemfile.lock by bundler-audit

HTTP Response Splitting (Early Hints) in Puma
Open

puma (2.15.3)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
Open

activesupport (4.2.5.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

ReDoS based DoS vulnerability in GlobalID
Open

globalid (0.3.6)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Information Exposure with Puma when used with Rails
Open

puma (2.15.3)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Denial of service via header parsing in Rack
Open

rack (1.6.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Ability to forge per-form CSRF tokens given a global CSRF token
Open

actionpack (4.2.5.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

HTTP Response Splitting vulnerability in puma
Open

puma (2.15.3)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible DoS Vulnerability in Action Controller Token Authentication
Open

actionpack (4.2.5.1)
Severity: Critical
Found in Gemfile.lock by bundler-audit

HTTP Smuggling via Transfer-Encoding Header in Puma
Open

puma (2.15.3)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Denial of service via multipart parsing in Rack
Open

rack (1.6.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Percent-encoded cookies can be used to overwrite existing prefixed cookie names
Open

rack (1.6.4)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Denial of Service Vulnerability in Rack Multipart Parsing
Open

rack (1.6.4)
Severity: Critical
Found in Gemfile.lock by bundler-audit
Severity
Category
Status
Source
Language