Showing 93 of 93 total issues
simple_form Gem for Ruby Incorrect Access Control for forms based on user input Open
simple_form (3.3.1)
- Read upRead up
- Exclude checks
Keepalive Connections Causing Denial Of Service in puma Open
puma (3.6.2)
- Read upRead up
- Exclude checks
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in puma Open
puma (3.6.2)
- Read upRead up
- Exclude checks
Potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore Open
activesupport (5.0.1)
- Read upRead up
- Exclude checks
Nokogiri gem, via libxml, is affected by DoS and RCE vulnerabilities Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
ReDoS based DoS vulnerability in Action Dispatch Open
actionpack (5.0.1)
- Read upRead up
- Exclude checks
Improper neutralization of data URIs may allow XSS in rails-html-sanitizer Open
rails-html-sanitizer (1.0.3)
- Read upRead up
- Exclude checks
Regular Expression Denial of Service in Addressable templates Open
addressable (2.5.0)
- Read upRead up
- Exclude checks
Possible Information Disclosure / Unintended Method Execution in Action Pack Open
actionpack (5.0.1)
- Read upRead up
- Exclude checks
Moderate severity vulnerability that affects nokogiri Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Possible DoS Vulnerability in Action Controller Token Authentication Open
actionpack (5.0.1)
- Read upRead up
- Exclude checks
Nokogiri gem, via libxslt, is affected by improper access control vulnerability Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Inefficient Regular Expression Complexity in Nokogiri Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Possible DoS Vulnerability in Active Record PostgreSQL adapter Open
activerecord (5.0.1)
- Read upRead up
- Exclude checks
Improper Handling of Unexpected Data Type in Nokogiri Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Percent-encoded cookies can be used to overwrite existing prefixed cookie names Open
rack (2.0.1)
- Read upRead up
- Exclude checks
Inefficient Regular Expression Complexity in rails-html-sanitizer Open
rails-html-sanitizer (1.0.3)
- Read upRead up
- Exclude checks
Ability to forge per-form CSRF tokens given a global CSRF token Open
actionpack (5.0.1)
- Read upRead up
- Exclude checks
ReDoS based DoS vulnerability in Active Support’s underscore Open
activesupport (5.0.1)
- Read upRead up
- Exclude checks
Nokogiri gem, via libxml, is affected by DoS vulnerabilities Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Directory traversal in Rack::Directory app bundled with Rack Open
rack (2.0.1)
- Read upRead up
- Exclude checks
i18n Gem for Ruby lib/i18n/core_ext/hash.rb Hash#slice() Function Hash Handling DoS Open
i18n (0.7.0)
- Read upRead up
- Exclude checks
Update packaged libxml2 (2.9.12 → 2.9.13) and libxslt (1.1.34 → 1.1.35) Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Nokogiri gem, via libxml2, is affected by multiple vulnerabilities Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Possible RCE escalation bug with Serialized Columns in Active Record Open
activerecord (5.0.1)
- Read upRead up
- Exclude checks
Update packaged dependency libxml2 from 2.9.10 to 2.9.12 Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Revert libxml2 behavior in Nokogiri gem that could cause XSS Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
ReDoS based DoS vulnerability in Action Dispatch Open
actionpack (5.0.1)
- Read upRead up
- Exclude checks
Possible exposure of information vulnerability in Action Pack Open
actionpack (5.0.1)
- Read upRead up
- Exclude checks
Possible XSS Vulnerability in Action View tag helpers Open
actionview (5.0.1)
- Read upRead up
- Exclude checks
Prototype pollution attack through jQuery $.extend Open
jquery-rails (4.2.2)
- Read upRead up
- Exclude checks
Nokogiri gem, via libxslt, is affected by multiple vulnerabilities Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Nokogiri::XML::Schema trusts input by default, exposing risk of an XXE vulnerability Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
libxml2 2.9.10 has an infinite loop in a certain end-of-file situation Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Possible XSS vulnerability with certain configurations of rails-html-sanitizer Open
rails-html-sanitizer (1.0.3)
- Read upRead up
- Exclude checks
Denial of Service Vulnerability in ActiveRecord’s PostgreSQL adapter Open
activerecord (5.0.1)
- Read upRead up
- Exclude checks
Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer Open
rails-html-sanitizer (1.0.3)
- Read upRead up
- Exclude checks
Nokogiri Command Injection Vulnerability via Nokogiri::CSS::Tokenizer#load_file Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
XSS vulnerabilities via data-parent, data-target, data-container in bootstrap Open
bootstrap (4.0.0.alpha4)
- Read upRead up
- Exclude checks
Doorkeeper gem does not revoke token for public clients Open
doorkeeper (4.2.0)
- Read upRead up
- Exclude checks
json Gem for Ruby Unsafe Object Creation Vulnerability (additional fix) Open
json (2.0.2)
- Read upRead up
- Exclude checks
Update bundled libxml2 to v2.10.3 to resolve multiple CVEs Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Nokogiri gem, via libxml, is affected by DoS vulnerabilities Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Integer Overflow or Wraparound in libxml2 affects Nokogiri Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Possible XSS vulnerability with certain configurations of rails-html-sanitizer Open
rails-html-sanitizer (1.0.3)
- Read upRead up
- Exclude checks
Possible shell escape sequence injection vulnerability in Rack Open
rack (2.0.1)
- Read upRead up
- Exclude checks
XSS vulnerability in rails-html-sanitizer Open
rails-html-sanitizer (1.0.3)
- Read upRead up
- Exclude checks
Broken Access Control vulnerability in Active Job Open
activejob (5.0.1)
- Read upRead up
- Exclude checks
Denial of Service Vulnerability in Rack Content-Disposition parsing Open
rack (2.0.1)
- Read upRead up
- Exclude checks
TZInfo relative path traversal vulnerability allows loading of arbitrary files Open
tzinfo (1.2.2)
- Read upRead up
- Exclude checks
Regular Expression Denial of Service in websocket-extensions (RubyGem) Open
websocket-extensions (0.1.2)
- Read upRead up
- Exclude checks
Nokogiri gem contains several vulnerabilities in libxml2 and libxslt Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Doorkeeper gem has stored XSS on authorization consent view Open
doorkeeper (4.2.0)
- Read upRead up
- Exclude checks
Nokogiri gem contains two upstream vulnerabilities in libxslt 1.1.29 Open
nokogiri (1.7.0)
- Read upRead up
- Exclude checks
Denial of Service Vulnerability in Rack Multipart Parsing Open
rack (2.0.1)
- Read upRead up
- Exclude checks
Possible information leak / session hijack vulnerability Open
rack (2.0.1)
- Read upRead up
- Exclude checks
rails-html-sanitizer 1.0.3 is vulnerable (CVE-2018-3741). Upgrade to 1.0.4 Open
rails-html-sanitizer (1.0.3)
- Read upRead up
- Exclude checks
Loofah 2.0.3 is vulnerable (CVE-2018-8048). Upgrade to 2.1.2 Open
loofah (2.0.3)
- Read upRead up
- Exclude checks
XSS vulnerability via data-target in bootstrap Open
bootstrap (4.0.0.alpha4)
- Read upRead up
- Exclude checks