deliveroo/routemaster

View on GitHub

Showing 30 of 30 total issues

Percent-encoded cookies can be used to overwrite existing prefixed cookie names
Open

rack (1.6.11)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Possible shell escape sequence injection vulnerability in Rack
Open

rack (1.6.11)
Severity: Minor
Found in Gemfile.lock by bundler-audit

sinatra does not validate expanded path matches
Open

sinatra (1.4.8)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Keepalive Connections Causing Denial Of Service in puma
Open

puma (3.7.1)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Directory traversal in Rack::Directory app bundled with Rack
Open

rack (1.6.11)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Information Exposure with Puma when used with Rails
Open

puma (3.7.1)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in puma
Open

puma (3.7.1)
Severity: Info
Found in Gemfile.lock by bundler-audit

HTTP Request Smuggling in puma
Open

puma (3.7.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Denial of service via header parsing in Rack
Open

rack (1.6.11)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Denial of service via multipart parsing in Rack
Open

rack (1.6.11)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Denial of Service Vulnerability in Rack Multipart Parsing
Open

rack (1.6.11)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Denial of Service Vulnerability in Rack Content-Disposition parsing
Open

rack (1.6.11)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Sinatra vulnerable to Reflected File Download attack
Open

sinatra (1.4.8)
Severity: Critical
Found in Gemfile.lock by bundler-audit

json Gem for Ruby Unsafe Object Creation Vulnerability (additional fix)
Open

json (2.1.0)
Severity: Critical
Found in Gemfile.lock by bundler-audit

HTTP Response Splitting vulnerability in puma
Open

puma (3.7.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Keepalive thread overload/DoS in puma
Open

puma (3.7.1)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Regular Expression Denial of Service in Addressable templates
Open

addressable (2.5.0)
Severity: Critical
Found in Gemfile.lock by bundler-audit

HTTP Smuggling via Transfer-Encoding Header in Puma
Open

puma (3.7.1)
Severity: Critical
Found in Gemfile.lock by bundler-audit

HTTP Smuggling via Transfer-Encoding Header in Puma
Open

puma (3.7.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

HTTP Response Splitting (Early Hints) in Puma
Open

puma (3.7.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit
Severity
Category
Status
Source
Language