fga-gpp-mds/Falko-2017.2-BackEnd

View on GitHub

Showing 91 of 95 total issues

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in puma
Open

puma (3.10.0)
Severity: Info
Found in Gemfile.lock by bundler-audit

HTTP Request Smuggling in puma
Open

puma (3.10.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

ReDoS based DoS vulnerability in GlobalID
Open

globalid (0.4.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Keepalive Connections Causing Denial Of Service in puma
Open

puma (3.10.0)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Information Exposure with Puma when used with Rails
Open

puma (3.10.0)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Possible XSS vulnerability in ActionView
Open

actionview (5.1.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Denial of Service Vulnerability in ActiveRecord’s PostgreSQL adapter
Open

activerecord (5.1.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible RCE escalation bug with Serialized Columns in Active Record
Open

activerecord (5.1.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Devise Gem for Ruby confirmation token validation with a blank string
Open

devise (4.3.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Loofah XSS Vulnerability
Open

loofah (2.1.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Nokogiri gem, via libxslt, is affected by multiple vulnerabilities
Open

nokogiri (1.8.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

HTTP Smuggling via Transfer-Encoding Header in Puma
Open

puma (3.10.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Devise Gem for Ruby Time-of-check Time-of-use race condition with lockable module
Open

devise (4.3.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Improper neutralization of data URIs may allow XSS in rails-html-sanitizer
Open

rails-html-sanitizer (1.0.3)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible Strong Parameters Bypass in ActionPack
Open

actionpack (5.1.4)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Loofah XSS Vulnerability
Open

loofah (2.1.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Update packaged dependency libxml2 from 2.9.10 to 2.9.12
Open

nokogiri (1.8.1)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Nokogiri::XML::Schema trusts input by default, exposing risk of an XXE vulnerability
Open

nokogiri (1.8.1)
Severity: Info
Found in Gemfile.lock by bundler-audit

Out-of-bounds Write in zlib affects Nokogiri
Open

nokogiri (1.8.1)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
Open

activesupport (5.1.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit
Severity
Category
Status
Source
Language