Showing 91 of 95 total issues
HTTP Response Splitting vulnerability in puma Open
puma (3.10.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Keepalive thread overload/DoS in puma Open
puma (3.10.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Code Injection vulnerability in CarrierWave::RMagick Open
carrierwave (1.2.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Potential XSS vulnerability in Action View Open
actionview (5.1.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Update bundled libxml2 to v2.10.3 to resolve multiple CVEs Open
nokogiri (1.8.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Inefficient Regular Expression Complexity in Nokogiri Open
nokogiri (1.8.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible Information Disclosure / Unintended Method Execution in Action Pack Open
actionpack (5.1.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
json Gem for Ruby Unsafe Object Creation Vulnerability (additional fix) Open
json (2.1.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Improper Handling of Unexpected Data Type in Nokogiri Open
nokogiri (1.8.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
HTTP Smuggling via Transfer-Encoding Header in Puma Open
puma (3.10.0)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Percent-encoded cookies can be used to overwrite existing prefixed cookie names Open
rack (2.0.3)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Ability to forge per-form CSRF tokens given a global CSRF token Open
actionpack (5.1.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible exposure of information vulnerability in Action Pack Open
actionpack (5.1.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible XSS Vulnerability in Action View tag helpers Open
actionview (5.1.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
CSRF Vulnerability in rails-ujs Open
actionview (5.1.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
ReDoS based DoS vulnerability in Active Support’s underscore Open
activesupport (5.1.4)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Improper neutralization of data URIs may allow XSS in Loofah Open
loofah (2.1.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Nokogiri Command Injection Vulnerability via Nokogiri::CSS::Tokenizer#load_file Open
nokogiri (1.8.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer Open
rails-html-sanitizer (1.0.3)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks
Server-side request forgery in CarrierWave Open
carrierwave (1.2.1)
- Read upRead up
- Create a ticketCreate a ticket
- Exclude checks