Showing 102 of 102 total issues
Keepalive Connections Causing Denial Of Service in puma Open
puma (3.11.0)
- Read upRead up
- Exclude checks
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in puma Open
puma (3.11.0)
- Read upRead up
- Exclude checks
Nokogiri gem, via libxslt, is affected by improper access control vulnerability Open
nokogiri (1.8.2)
- Read upRead up
- Exclude checks
Improper neutralization of data URIs may allow XSS in rails-html-sanitizer Open
rails-html-sanitizer (1.0.4)
- Read upRead up
- Exclude checks
Possible exposure of information vulnerability in Action Pack Open
actionpack (5.1.6)
- Read upRead up
- Exclude checks
Possible RCE escalation bug with Serialized Columns in Active Record Open
activerecord (5.1.6)
- Read upRead up
- Exclude checks
Nokogiri Command Injection Vulnerability via Nokogiri::CSS::Tokenizer#load_file Open
nokogiri (1.8.2)
- Read upRead up
- Exclude checks
Possible Information Disclosure / Unintended Method Execution in Action Pack Open
actionpack (5.1.6)
- Read upRead up
- Exclude checks
Possible XSS vulnerability with certain configurations of rails-html-sanitizer Open
rails-html-sanitizer (1.0.4)
- Read upRead up
- Exclude checks
Ability to forge per-form CSRF tokens given a global CSRF token Open
actionpack (5.1.6)
- Read upRead up
- Exclude checks
Possible XSS Vulnerability in Action View tag helpers Open
actionview (5.1.6)
- Read upRead up
- Exclude checks