rails-stall/stall

View on GitHub

Showing 168 of 168 total issues

CSRF Vulnerability in rails-ujs
Open

actionview (4.2.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

ReDoS based DoS vulnerability in GlobalID
Open

globalid (0.4.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

simple_form Gem for Ruby Incorrect Access Control for forms based on user input
Open

simple_form (3.4.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible XSS vulnerability in ActionView
Open

actionview (4.2.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Denial of Service Vulnerability in Rack Multipart Parsing
Open

rack (1.6.4)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Possible Strong Parameters Bypass in ActionPack
Open

actionpack (4.2.4)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Possible DoS Vulnerability in Active Record PostgreSQL adapter
Open

activerecord (4.2.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Percent-encoded cookies can be used to overwrite existing prefixed cookie names
Open

rack (1.6.4)
Severity: Critical
Found in Gemfile.lock by bundler-audit

OS Command Injection in Rake
Open

rake (10.4.2)
Severity: Critical
Found in Gemfile.lock by bundler-audit

ReDoS based DoS vulnerability in Action Dispatch
Open

actionpack (4.2.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

ReDoS based DoS vulnerability in Action Dispatch
Open

actionpack (4.2.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible RCE escalation bug with Serialized Columns in Active Record
Open

activerecord (4.2.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Potential XSS vulnerability in Action View
Open

actionview (4.2.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

ReDoS based DoS vulnerability in Active Support’s underscore
Open

activesupport (4.2.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
Open

activesupport (4.2.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

haml failure to escape single quotes
Open

haml (4.0.7)
Severity: Minor
Found in Gemfile.lock by bundler-audit

json Gem for Ruby Unsafe Object Creation Vulnerability (additional fix)
Open

json (1.8.3)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Possible Information Disclosure / Unintended Method Execution in Action Pack
Open

actionpack (4.2.4)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Denial of service via header parsing in Rack
Open

rack (1.6.4)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible DoS Vulnerability in Action Controller Token Authentication
Open

actionpack (4.2.4)
Severity: Critical
Found in Gemfile.lock by bundler-audit
Severity
Category
Status
Source
Language