ServiceInnovationLab/pancake-backend

View on GitHub

Showing 308 of 313 total issues

Information Exposure with Puma when used with Rails
Open

puma (3.12.1)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Keepalive Connections Causing Denial Of Service in puma
Open

puma (3.12.1)
Severity: Critical
Found in Gemfile.lock by bundler-audit

HTTP Request Smuggling in puma
Open

puma (3.12.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

ReDoS based DoS vulnerability in GlobalID
Open

globalid (0.4.2)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in puma
Open

puma (3.12.1)
Severity: Info
Found in Gemfile.lock by bundler-audit

Class has too many lines. [108/100]
Open

class RebateForm < ApplicationRecord
include Discard::Model
audited only: [:discarded_at], on: :update
 
has_many :signatures, dependent: :destroy
Severity: Minor
Found in app/models/rebate_form.rb by rubocop

Update packaged libxml2 (2.9.12 → 2.9.13) and libxslt (1.1.34 → 1.1.35)
Open

nokogiri (1.10.5)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Remote shell execution vulnerability when applying commands from user input
Open

image_processing (1.9.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Improper neutralization of data URIs may allow XSS in Loofah
Open

loofah (2.3.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Uncontrolled Recursion in Loofah
Open

loofah (2.3.1)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Out-of-bounds Write in zlib affects Nokogiri
Open

nokogiri (1.10.5)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Directory traversal in Rack::Directory app bundled with Rack
Open

rack (2.0.7)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Denial of Service (DoS) in Nokogiri on JRuby
Open

nokogiri (1.10.5)
Severity: Critical
Found in Gemfile.lock by bundler-audit

XML Injection in Xerces Java affects Nokogiri
Open

nokogiri (1.10.5)
Severity: Minor
Found in Gemfile.lock by bundler-audit

CSS injection with width and height options
Open

chartkick (3.3.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Nokogiri::XML::Schema trusts input by default, exposing risk of an XXE vulnerability
Open

nokogiri (1.10.5)
Severity: Info
Found in Gemfile.lock by bundler-audit

json Gem for Ruby Unsafe Object Creation Vulnerability (additional fix)
Open

json (2.2.0)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Integer Overflow or Wraparound in libxml2 affects Nokogiri
Open

nokogiri (1.10.5)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Update packaged dependency libxml2 from 2.9.10 to 2.9.12
Open

nokogiri (1.10.5)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Percent-encoded cookies can be used to overwrite existing prefixed cookie names
Open

rack (2.0.7)
Severity: Critical
Found in Gemfile.lock by bundler-audit
Severity
Category
Status
Source
Language