BindaCMS/binda

View on GitHub

Showing 81 of 81 total issues

ReDoS based DoS vulnerability in GlobalID
Open

    globalid (0.4.2)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Advisory: CVE-2023-22799

URL: https://github.com/rails/globalid/releases/tag/v1.0.1

Solution: upgrade to >= 1.0.1

File binda.bundle.js has 699 lines of code (exceeds 250 allowed). Consider refactoring.
Open

/******/ (function(modules) { // webpackBootstrap
/******/     // The module cache
/******/     var installedModules = {};
/******/
/******/     // The require function
Severity: Major
Found in app/assets/javascripts/binda/dist/binda.bundle.js - About 1 day to fix

    Code Injection vulnerability in CarrierWave::RMagick
    Open

        carrierwave (1.2.3)
    Severity: Critical
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2021-21305

    Criticality: High

    URL: https://github.com/carrierwaveuploader/carrierwave/security/advisories/GHSA-cf3w-g86h-35x4

    Solution: upgrade to ~> 1.3.2, >= 2.1.1

    json Gem for Ruby Unsafe Object Creation Vulnerability (additional fix)
    Open

        json (2.2.0)
    Severity: Critical
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2020-10663

    Criticality: High

    URL: https://www.ruby-lang.org/en/news/2020/03/19/json-dos-cve-2020-10663/

    Solution: upgrade to >= 2.3.0

    Inefficient Regular Expression Complexity in Loofah
    Open

        loofah (2.3.1)
    Severity: Critical
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2022-23514

    Criticality: High

    URL: https://github.com/flavorjones/loofah/security/advisories/GHSA-486f-hjj9-9vhh

    Solution: upgrade to >= 2.19.1

    Integer Overflow or Wraparound in libxml2 affects Nokogiri
    Open

        nokogiri (1.10.5)
    Severity: Critical
    Found in Gemfile.lock by bundler-audit

    Advisory:

    Criticality: High

    URL: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-cgx6-hpwq-fhv5

    Solution: upgrade to >= 1.13.5

    Improper neutralization of data URIs may allow XSS in rails-html-sanitizer
    Open

        rails-html-sanitizer (1.3.0)
    Severity: Minor
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2022-23518

    Criticality: Medium

    URL: https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-mcvf-2q2m-x72m

    Solution: upgrade to >= 1.4.4

    Server-side request forgery in CarrierWave
    Open

        carrierwave (1.2.3)
    Severity: Minor
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2021-21288

    Criticality: Medium

    URL: https://github.com/carrierwaveuploader/carrierwave/security/advisories/GHSA-fwcm-636p-68r5

    Solution: upgrade to ~> 1.3.2, >= 2.1.1

    Out-of-bounds Write in zlib affects Nokogiri
    Open

        nokogiri (1.10.5)
    Severity: Critical
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2018-25032

    Criticality: High

    URL: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-v6gp-9mmm-c6p5

    Solution: upgrade to >= 1.13.4

    Improper Handling of Unexpected Data Type in Nokogiri
    Open

        nokogiri (1.10.5)
    Severity: Critical
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2022-29181

    Criticality: High

    URL: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-xh29-r2w5-wx8m

    Solution: upgrade to >= 1.13.6

    Directory traversal in Rack::Directory app bundled with Rack
    Open

        rack (2.0.7)
    Severity: Critical
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2020-8161

    Criticality: High

    URL: https://groups.google.com/forum/#!topic/ruby-security-ann/T4ZIsfRf2eA

    Solution: upgrade to ~> 2.1.3, >= 2.2.0

    Uncontrolled Recursion in Loofah
    Open

        loofah (2.3.1)
    Severity: Critical
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2022-23516

    Criticality: High

    URL: https://github.com/flavorjones/loofah/security/advisories/GHSA-3x8r-x6xp-q4vm

    Solution: upgrade to >= 2.19.1

    Improper neutralization of data URIs may allow XSS in Loofah
    Open

        loofah (2.3.1)
    Severity: Minor
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2022-23515

    Criticality: Medium

    URL: https://github.com/flavorjones/loofah/security/advisories/GHSA-228g-948r-83gx

    Solution: upgrade to >= 2.19.1

    Update packaged dependency libxml2 from 2.9.10 to 2.9.12
    Open

        nokogiri (1.10.5)
    Severity: Critical
    Found in Gemfile.lock by bundler-audit

    Advisory:

    Criticality: High

    URL: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-7rrm-v45f-jp64

    Solution: upgrade to >= 1.11.4

    Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby
    Open

        nokogiri (1.10.5)
    Severity: Critical
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2021-41098

    Criticality: High

    URL: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-2rr5-8q37-2w7h

    Solution: upgrade to >= 1.12.5

    Devise Gem for Ruby Time-of-check Time-of-use race condition with lockable module
    Open

        devise (4.4.3)
    Severity: Minor
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2019-5421

    Criticality: Critical

    URL: https://github.com/plataformatec/devise/issues/4981

    Solution: upgrade to >= 4.6.0

    Cross-Site Scripting in Kaminari via original_script_name parameter
    Open

        kaminari (1.1.1)
    Severity: Minor
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2020-11082

    Criticality: Medium

    URL: https://github.com/kaminari/kaminari/security/advisories/GHSA-r5jw-62xg-j433

    Solution: upgrade to >= 1.2.1

    XML Injection in Xerces Java affects Nokogiri
    Open

        nokogiri (1.10.5)
    Severity: Minor
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2022-23437

    Criticality: Medium

    URL: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-xxx9-3xcr-gjj3

    Solution: upgrade to >= 1.13.4

    Inefficient Regular Expression Complexity in Nokogiri
    Open

        nokogiri (1.10.5)
    Severity: Critical
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2022-24836

    Criticality: High

    URL: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-crjr-9rc5-ghw8

    Solution: upgrade to >= 1.13.4

    Possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer
    Open

        rails-html-sanitizer (1.3.0)
    Severity: Minor
    Found in Gemfile.lock by bundler-audit

    Advisory: CVE-2022-32209

    Criticality: Medium

    URL: https://groups.google.com/g/rubyonrails-security/c/ce9PhUANQ6s

    Solution: upgrade to >= 1.4.3

    Severity
    Category
    Status
    Source
    Language