hpi-swt2/sport-portal

View on GitHub

Showing 179 of 239 total issues

ReDoS based DoS vulnerability in GlobalID
Open

globalid (0.4.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Information Exposure with Puma when used with Rails
Open

puma (3.11.2)
Severity: Critical
Found in Gemfile.lock by bundler-audit

CSRF vulnerability in OmniAuth's request phase
Open

omniauth (1.8.1)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in puma
Open

puma (3.11.2)
Severity: Info
Found in Gemfile.lock by bundler-audit

HTTP Request Smuggling in puma
Open

puma (3.11.2)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Keepalive Connections Causing Denial Of Service in puma
Open

puma (3.11.2)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Possible timing attack in derivation_endpoint
Open

shrine (2.8.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Regular Expression Denial of Service in Addressable templates
Open

addressable (2.5.2)
Severity: Critical
Found in Gemfile.lock by bundler-audit

HTTP Response Splitting (Early Hints) in Puma
Open

puma (3.11.2)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Improper neutralization of data URIs may allow XSS in rails-html-sanitizer
Open

rails-html-sanitizer (1.0.3)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible Information Disclosure / Unintended Method Execution in Action Pack
Open

actionpack (5.1.4)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Possible exposure of information vulnerability in Action Pack
Open

actionpack (5.1.4)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Loofah XSS Vulnerability
Open

loofah (2.1.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Older releases of better_errors open to Cross-Site Request Forgery attack
Open

better_errors (2.4.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

XML Injection in Xerces Java affects Nokogiri
Open

nokogiri (1.8.2)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Out-of-bounds Write in zlib affects Nokogiri
Open

nokogiri (1.8.2)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Denial of Service (DoS) in Nokogiri on JRuby
Open

nokogiri (1.8.2)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby
Open

nokogiri (1.8.2)
Severity: Critical
Found in Gemfile.lock by bundler-audit

HTTP Smuggling via Transfer-Encoding Header in Puma
Open

puma (3.11.2)
Severity: Critical
Found in Gemfile.lock by bundler-audit

ReDoS based DoS vulnerability in Action Dispatch
Open

actionpack (5.1.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit
Severity
Category
Status
Source
Language