NIT-dgp/cat-forum

View on GitHub

Showing 145 of 145 total issues

Possible Information Disclosure / Unintended Method Execution in Action Pack
Open

actionpack (4.1.8)
Severity: Critical
Found in Gemfile.lock by bundler-audit

json Gem for Ruby Unsafe Object Creation Vulnerability (additional fix)
Open

json (1.8.3)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Possible XSS vulnerability in ActionView
Open

actionview (4.1.8)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible RCE escalation bug with Serialized Columns in Active Record
Open

activerecord (4.1.8)
Severity: Minor
Found in Gemfile.lock by bundler-audit

haml failure to escape single quotes
Open

haml (4.0.7)
Severity: Minor
Found in Gemfile.lock by bundler-audit

CSRF Vulnerability in rails-ujs
Open

actionview (4.1.8)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Code Injection vulnerability in CarrierWave::RMagick
Open

carrierwave (0.11.2)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Denial of service via multipart parsing in Rack
Open

rack (1.5.5)
Severity: Minor
Found in Gemfile.lock by bundler-audit

RDoc OS command injection vulnerability
Open

rdoc (4.2.2)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Possible Strong Parameters Bypass in ActionPack
Open

actionpack (4.1.8)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Denial of service via header parsing in Rack
Open

rack (1.5.5)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Percent-encoded cookies can be used to overwrite existing prefixed cookie names
Open

rack (1.5.5)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Denial of Service Vulnerability in Rack Content-Disposition parsing
Open

rack (1.5.5)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible XSS Vulnerability in Action View tag helpers
Open

actionview (4.1.8)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Potential XSS vulnerability in jQuery
Open

jquery-rails (3.1.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible shell escape sequence injection vulnerability in Rack
Open

rack (1.5.5)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Directory traversal in Rack::Directory app bundled with Rack
Open

rack (1.5.5)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Denial of Service Vulnerability in Rack Multipart Parsing
Open

rack (1.5.5)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Ability to forge per-form CSRF tokens given a global CSRF token
Open

actionpack (4.1.8)
Severity: Minor
Found in Gemfile.lock by bundler-audit

ReDoS based DoS vulnerability in Action Dispatch
Open

actionpack (4.1.8)
Severity: Minor
Found in Gemfile.lock by bundler-audit
Severity
Category
Status
Source
Language