Showing 91 of 95 total issues
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in puma Open
puma (3.10.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
HTTP Request Smuggling in puma Open
puma (3.10.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
ReDoS based DoS vulnerability in GlobalID Open
globalid (0.4.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Keepalive Connections Causing Denial Of Service in puma Open
puma (3.10.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Information Exposure with Puma when used with Rails Open
puma (3.10.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible XSS vulnerability in ActionView Open
actionview (5.1.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Denial of Service Vulnerability in ActiveRecord’s PostgreSQL adapter Open
activerecord (5.1.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible RCE escalation bug with Serialized Columns in Active Record Open
activerecord (5.1.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Devise Gem for Ruby confirmation token validation with a blank string Open
devise (4.3.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Loofah XSS Vulnerability Open
loofah (2.1.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri gem, via libxslt, is affected by multiple vulnerabilities Open
nokogiri (1.8.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
HTTP Smuggling via Transfer-Encoding Header in Puma Open
puma (3.10.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Devise Gem for Ruby Time-of-check Time-of-use race condition with lockable module Open
devise (4.3.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Improper neutralization of data URIs may allow XSS in rails-html-sanitizer Open
rails-html-sanitizer (1.0.3)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible Strong Parameters Bypass in ActionPack Open
actionpack (5.1.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Loofah XSS Vulnerability Open
loofah (2.1.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Update packaged dependency libxml2 from 2.9.10 to 2.9.12 Open
nokogiri (1.8.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri::XML::Schema trusts input by default, exposing risk of an XXE vulnerability Open
nokogiri (1.8.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Out-of-bounds Write in zlib affects Nokogiri Open
nokogiri (1.8.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore Open
activesupport (5.1.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks