smcgov/ohana-sms-smc

View on GitHub

Showing 57 of 57 total issues

Unsanitized input leading to code injection in Dalli
Open

dalli (2.7.10)
Severity: Info
Found in Gemfile.lock by bundler-audit

ReDoS based DoS vulnerability in GlobalID
Open

globalid (0.4.2)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Inefficient Regular Expression Complexity in Loofah
Open

loofah (2.5.0)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Update packaged libxml2 (2.9.12 → 2.9.13) and libxslt (1.1.34 → 1.1.35)
Open

nokogiri (1.10.9)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Inefficient Regular Expression Complexity in Nokogiri
Open

nokogiri (1.10.9)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Out-of-bounds Write in zlib affects Nokogiri
Open

nokogiri (1.10.9)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Possible XSS vulnerability with certain configurations of rails-html-sanitizer
Open

rails-html-sanitizer (1.3.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Inefficient Regular Expression Complexity in rails-html-sanitizer
Open

rails-html-sanitizer (1.3.0)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Update bundled libxml2 to v2.10.3 to resolve multiple CVEs
Open

nokogiri (1.10.9)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Uncontrolled Recursion in Loofah
Open

loofah (2.5.0)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Denial of Service (DoS) in Nokogiri on JRuby
Open

nokogiri (1.10.9)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Improper neutralization of data URIs may allow XSS in rails-html-sanitizer
Open

rails-html-sanitizer (1.3.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer
Open

rails-html-sanitizer (1.3.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Integer Overflow or Wraparound in libxml2 affects Nokogiri
Open

nokogiri (1.10.9)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Improper Handling of Unexpected Data Type in Nokogiri
Open

nokogiri (1.10.9)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Improper neutralization of data URIs may allow XSS in Loofah
Open

loofah (2.5.0)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Update packaged dependency libxml2 from 2.9.10 to 2.9.12
Open

nokogiri (1.10.9)
Severity: Critical
Found in Gemfile.lock by bundler-audit

Nokogiri::XML::Schema trusts input by default, exposing risk of an XXE vulnerability
Open

nokogiri (1.10.9)
Severity: Info
Found in Gemfile.lock by bundler-audit

XML Injection in Xerces Java affects Nokogiri
Open

nokogiri (1.10.9)
Severity: Minor
Found in Gemfile.lock by bundler-audit

Regular Expression Denial of Service in Addressable templates
Open

addressable (2.5.2)
Severity: Critical
Found in Gemfile.lock by bundler-audit
Severity
Category
Status
Source
Language