Showing 218 of 218 total issues
Devise Gem for Ruby Time-of-check Time-of-use race condition with lockable module Open
devise (3.5.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
CSRF vulnerability in OmniAuth's request phase Open
omniauth (1.2.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
HTTP Request Smuggling in puma Open
puma (2.14.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
OS Command Injection in Rake Open
rake (10.4.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Devise Gem for Ruby confirmation token validation with a blank string Open
devise (3.5.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
RDoc OS command injection vulnerability Open
rdoc (4.2.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Ability to forge per-form CSRF tokens given a global CSRF token Open
actionpack (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Potential XSS vulnerability in Action View Open
actionview (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
ReDoS based DoS vulnerability in Active Support’s underscore Open
activesupport (4.2.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Denial of service via multipart parsing in Rack Open
rack (1.6.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
HTTP Response Splitting (Early Hints) in Puma Open
puma (2.14.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Cross-site Scripting in Sidekiq Open
sidekiq (3.5.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Sinatra vulnerable to Reflected File Download attack Open
sinatra (1.4.6)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
sinatra does not validate expanded path matches Open
sinatra (1.4.6)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Information Exposure with Puma when used with Rails Open
puma (2.14.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
HTTP Smuggling via Transfer-Encoding Header in Puma Open
puma (2.14.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Denial of Service Vulnerability in Rack Multipart Parsing Open
rack (1.6.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Keepalive Connections Causing Denial Of Service in puma Open
puma (2.14.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible shell escape sequence injection vulnerability in Rack Open
rack (1.6.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Denial of service in sidekiq Open
sidekiq (3.5.2)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks