Showing 109 of 109 total issues
Denial of Service Vulnerability in Rack Content-Disposition parsing Open
rack (1.6.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Directory traversal in Rack::Directory app bundled with Rack Open
rack (1.6.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible Information Disclosure / Unintended Method Execution in Action Pack Open
actionpack (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible RCE escalation bug with Serialized Columns in Active Record Open
activerecord (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible DoS Vulnerability in Active Record PostgreSQL adapter Open
activerecord (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Devise Gem for Ruby confirmation token validation with a blank string Open
devise (3.5.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
HTTP Smuggling via Transfer-Encoding Header in Puma Open
puma (2.14.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible shell escape sequence injection vulnerability in Rack Open
rack (1.6.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
ReDoS based DoS vulnerability in Action Dispatch Open
actionpack (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Keepalive thread overload/DoS in puma Open
puma (2.14.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Information Exposure with Puma when used with Rails Open
puma (2.14.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
ReDoS based DoS vulnerability in Active Support’s underscore Open
activesupport (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
HTTP Response Splitting vulnerability in puma Open
puma (2.14.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
HTTP Request Smuggling in puma Open
puma (2.14.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Cross-site Scripting in Sidekiq Open
sidekiq (3.5.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Ability to forge per-form CSRF tokens given a global CSRF token Open
actionpack (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
CSRF Vulnerability in rails-ujs Open
actionview (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Denial of service via header parsing in Rack Open
rack (1.6.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Denial of service in sidekiq Open
sidekiq (3.5.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Keepalive Connections Causing Denial Of Service in puma Open
puma (2.14.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
json Gem for Ruby Unsafe Object Creation Vulnerability (additional fix) Open
json (1.8.3)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
CSRF vulnerability in OmniAuth's request phase Open
omniauth (1.2.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
OS Command Injection in Rake Open
rake (10.4.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Denial of Service Vulnerability in ActiveRecord’s PostgreSQL adapter Open
activerecord (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
HTTP Response Splitting (Early Hints) in Puma Open
puma (2.14.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Denial of service via multipart parsing in Rack Open
rack (1.6.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Percent-encoded cookies can be used to overwrite existing prefixed cookie names Open
rack (1.6.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
RDoc OS command injection vulnerability Open
rdoc (4.2.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible XSS vulnerability in ActionView Open
actionview (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore Open
activesupport (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
ReDoS based DoS vulnerability in GlobalID Open
globalid (0.3.6)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in puma Open
puma (2.14.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible XSS Vulnerability in Action View tag helpers Open
actionview (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
HTTP Smuggling via Transfer-Encoding Header in Puma Open
puma (2.14.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Denial of Service Vulnerability in Rack Multipart Parsing Open
rack (1.6.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible DoS Vulnerability in Action Controller Token Authentication Open
actionpack (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible Strong Parameters Bypass in ActionPack Open
actionpack (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
ReDoS based DoS vulnerability in Action Dispatch Open
actionpack (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Devise Gem for Ruby Time-of-check Time-of-use race condition with lockable module Open
devise (3.5.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Sinatra vulnerable to Reflected File Download attack Open
sinatra (1.4.6)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
sinatra does not validate expanded path matches Open
sinatra (1.4.6)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Potential XSS vulnerability in Action View Open
actionview (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
XSS vulnerability via data-target in bootstrap-sass Open
bootstrap-sass (3.3.5.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Out-of-bounds Write in zlib affects Nokogiri Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri gem, via libxml, is affected by DoS and RCE vulnerabilities Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Update packaged libxml2 (2.9.12 → 2.9.13) and libxslt (1.1.34 → 1.1.35) Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri gem, via libxslt, is affected by improper access control vulnerability Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Improper Handling of Unexpected Data Type in Nokogiri Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Potential XSS vulnerability in jQuery Open
jquery-rails (4.0.5)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Update packaged dependency libxml2 from 2.9.10 to 2.9.12 Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Denial of Service (DoS) in Nokogiri on JRuby Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible XSS vulnerability with certain configurations of rails-html-sanitizer Open
rails-html-sanitizer (1.0.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
i18n Gem for Ruby lib/i18n/core_ext/hash.rb Hash#slice() Function Hash Handling DoS Open
i18n (0.7.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Inefficient Regular Expression Complexity in Loofah Open
loofah (2.0.3)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Loofah XSS Vulnerability Open
loofah (2.0.3)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Inefficient Regular Expression Complexity in rails-html-sanitizer Open
rails-html-sanitizer (1.0.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri gem, via libxslt, is affected by multiple vulnerabilities Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Loofah XSS Vulnerability Open
loofah (2.0.3)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri gem, via libxml2, is affected by multiple vulnerabilities Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Loofah XSS Vulnerability Open
loofah (2.0.3)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
XML Injection in Xerces Java affects Nokogiri Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri gem contains two upstream vulnerabilities in libxslt 1.1.29 Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri gem, via libxml, is affected by DoS vulnerabilities Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Regular Expression Denial of Service in Addressable templates Open
addressable (2.3.8)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri Command Injection Vulnerability via Nokogiri::CSS::Tokenizer#load_file Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri::XML::Schema trusts input by default, exposing risk of an XXE vulnerability Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
libxml2 2.9.10 has an infinite loop in a certain end-of-file situation Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Revert libxml2 behavior in Nokogiri gem that could cause XSS Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Path Traversal in Sprockets Open
sprockets (3.4.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
OmniAuth's lib/omniauth/failure_endpoint.rb
does not escape message_key
value Open
omniauth (1.2.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Insecure Source URI found: git://github.com/atzorvas/omniauth-wordpress-oauth2-plugin.git Open
remote: git://github.com/atzorvas/omniauth-wordpress-oauth2-plugin.git
- Create a ticketCreate a ticket
- Exclude checks
XSS vulnerability in bootstrap-sass Open
bootstrap-sass (3.3.5.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri gem, via libxml, is affected by DoS vulnerabilities Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Inefficient Regular Expression Complexity in Nokogiri Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Prototype pollution attack through jQuery $.extend Open
jquery-rails (4.0.5)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Integer Overflow or Wraparound in libxml2 affects Nokogiri Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
omniauth leaks authenticity token in callback params Open
omniauth (1.2.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible XSS vulnerability with certain configurations of rails-html-sanitizer Open
rails-html-sanitizer (1.0.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer Open
rails-html-sanitizer (1.0.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Update bundled libxml2 to v2.10.3 to resolve multiple CVEs Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Moderate severity vulnerability that affects nokogiri Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri gem contains several vulnerabilities in libxml2 and libxslt Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible information leak / session hijack vulnerability Open
rack (1.6.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Denial of Service Vulnerability in Action View Open
actionview (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
rack-protection gem timing attack vulnerability when validating CSRF token Open
rack-protection (1.5.3)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Object leak vulnerability for wildcard controller routes in Action Pack Open
actionpack (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Unsafe Query Generation Risk in Active Record Open
activerecord (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible Object Leak and Denial of Service attack in Action Pack Open
actionpack (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Devise Gem for Ruby Unauthorized Access Using Remember Me Cookie Open
devise (3.5.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Path traversal is possible via backslash characters on Windows. Open
rack-protection (1.5.3)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri gem contains several vulnerabilities in libxml2 Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri gem contains a heap-based buffer overflow vulnerability in libxml2 Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible XSS vulnerability in rails-html-sanitizer Open
rails-html-sanitizer (1.0.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
File Content Disclosure in Action View Open
actionview (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
XSS vulnerability in rails-html-sanitizer Open
rails-html-sanitizer (1.0.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
TZInfo relative path traversal vulnerability allows loading of arbitrary files Open
tzinfo (1.2.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible remote code execution vulnerability in Action Pack Open
actionpack (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nested attributes rejection proc bypass in Active Record Open
activerecord (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible XSS vulnerability in Rack Open
rack (1.6.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible Input Validation Circumvention in Active Model Open
activemodel (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Denial of service or RCE from libxml2 and libxslt Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible XSS vulnerability in rails-html-sanitizer Open
rails-html-sanitizer (1.0.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Broken Access Control vulnerability in Active Job Open
activejob (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible XSS Vulnerability in Action View Open
actionview (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Timing attack vulnerability in basic authentication in Action Controller. Open
actionpack (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Potential remote code execution of user-provided local names in ActionView Open
actionview (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible Information Leak Vulnerability in Action View Open
actionview (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri gem contains several vulnerabilities in libxml2 and libxslt Open
nokogiri (1.6.6.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks