paweljw/bookstore-backend

View on GitHub

Showing 102 of 102 total issues

Keepalive Connections Causing Denial Of Service in puma
Open

puma (3.11.0)
Severity: Critical
Found in Gemfile.lock by bundler-audit

ReDoS based DoS vulnerability in GlobalID
Open

globalid (0.4.1)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in puma
Open

puma (3.11.0)
Severity: Info
Found in Gemfile.lock by bundler-audit

HTTP Request Smuggling in puma
Open

puma (3.11.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Information Exposure with Puma when used with Rails
Open

puma (3.11.0)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Potential XSS vulnerability in Action View
Open

actionview (5.1.6)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible XSS vulnerability in ActionView
Open

actionview (5.1.6)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Nokogiri gem, via libxslt, is affected by improper access control vulnerability
Open

nokogiri (1.8.2)
Severity: Minor
Found in Gemfile.lock by bundler-audit

HTTP Smuggling via Transfer-Encoding Header in Puma
Open

puma (3.11.0)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Improper neutralization of data URIs may allow XSS in rails-html-sanitizer
Open

rails-html-sanitizer (1.0.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible exposure of information vulnerability in Action Pack
Open

actionpack (5.1.6)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Possible RCE escalation bug with Serialized Columns in Active Record
Open

activerecord (5.1.6)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Nokogiri Command Injection Vulnerability via Nokogiri::CSS::Tokenizer#load_file
Open

nokogiri (1.8.2)
Severity: Minor
Found in Gemfile.lock by bundler-audit

XML Injection in Xerces Java affects Nokogiri
Open

nokogiri (1.8.2)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Out-of-bounds Write in zlib affects Nokogiri
Open

nokogiri (1.8.2)
Severity: Critical
Found in Gemfile.lock by bundler-audit

HTTP Response Splitting (Early Hints) in Puma
Open

puma (3.11.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible Information Disclosure / Unintended Method Execution in Action Pack
Open

actionpack (5.1.6)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Possible XSS vulnerability with certain configurations of rails-html-sanitizer
Open

rails-html-sanitizer (1.0.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Ability to forge per-form CSRF tokens given a global CSRF token
Open

actionpack (5.1.6)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible XSS Vulnerability in Action View tag helpers
Open

actionview (5.1.6)
Severity: Minor
Found in Gemfile.lock by bundler-audit
Severity
Category
Status
Source
Language