Search CVE reports
51 – 60 of 148 results
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
7 affected packages
rails, rails-4.0, ruby-actionpack-3.2, ruby-activemodel-3.2, ruby-activerecord-3.2...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
rails | Not affected | Not affected | Needs evaluation | Needs evaluation |
rails-4.0 | Not in release | Not in release | Not in release | Not in release |
ruby-actionpack-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activemodel-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activerecord-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activesupport-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-rails-3.2 | Not in release | Not in release | Not in release | Not in release |
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
7 affected packages
rails, rails-4.0, ruby-actionpack-3.2, ruby-activemodel-3.2, ruby-activerecord-3.2...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
rails | Not affected | Not affected | Needs evaluation | Needs evaluation |
rails-4.0 | Not in release | Not in release | Not in release | Not in release |
ruby-actionpack-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activemodel-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activerecord-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activesupport-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-rails-3.2 | Not in release | Not in release | Not in release | Not in release |
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
7 affected packages
rails, rails-4.0, ruby-actionpack-3.2, ruby-activemodel-3.2, ruby-activerecord-3.2...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
rails | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
rails-4.0 | Not in release | Not in release | Not in release | Not in release |
ruby-actionpack-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activemodel-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activerecord-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activesupport-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-rails-3.2 | Not in release | Not in release | Not in release | Not in release |
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end...
7 affected packages
rails, rails-4.0, ruby-actionpack-3.2, ruby-activemodel-3.2, ruby-activerecord-3.2...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
rails | Not affected | Not affected | Needs evaluation | Needs evaluation |
rails-4.0 | Not in release | Not in release | Not in release | Not in release |
ruby-actionpack-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activemodel-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activerecord-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activesupport-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-rails-3.2 | Not in release | Not in release | Not in release | Not in release |
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.
7 affected packages
rails, rails-4.0, ruby-actionpack-3.2, ruby-activemodel-3.2, ruby-activerecord-3.2...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
rails | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
rails-4.0 | Not in release | Not in release | Not in release | Not in release |
ruby-actionpack-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activemodel-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activerecord-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activesupport-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-rails-3.2 | Not in release | Not in release | Not in release | Not in release |
In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks....
7 affected packages
rails, rails-4.0, ruby-actionpack-3.2, ruby-activemodel-3.2, ruby-activerecord-3.2...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
rails | Not affected | Not affected | Needs evaluation | Needs evaluation |
rails-4.0 | Not in release | Not in release | Not in release | Not in release |
ruby-actionpack-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activemodel-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activerecord-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activesupport-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-rails-3.2 | Not in release | Not in release | Not in release | Not in release |
In Action View before versions 5.2.4.4 and 6.0.3.3 there is a potential Cross-Site Scripting (XSS) vulnerability in Action View's translation helpers. Views that allow the user to control the default (not found) value of the `t`...
7 affected packages
rails-4.0, ruby-actionpack-3.2, ruby-activemodel-3.2, ruby-activerecord-3.2, ruby-activesupport-3.2...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
rails-4.0 | Not in release | Not in release | Not in release | Not in release |
ruby-actionpack-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activemodel-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activerecord-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activesupport-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-rails-3.2 | Not in release | Not in release | Not in release | Not in release |
rails | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with...
7 affected packages
rails, rails-4.0, ruby-actionpack-3.2, ruby-activemodel-3.2, ruby-activerecord-3.2...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
rails | — | — | — | Not affected |
rails-4.0 | — | — | — | Not in release |
ruby-actionpack-3.2 | — | — | — | Not in release |
ruby-activemodel-3.2 | — | — | — | Not in release |
ruby-activerecord-3.2 | — | — | — | Not in release |
ruby-activesupport-3.2 | — | — | — | Not in release |
ruby-rails-3.2 | — | — | — | Not in release |
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.
7 affected packages
rails-4.0, ruby-actionpack-3.2, ruby-activemodel-3.2, ruby-activerecord-3.2, ruby-activesupport-3.2...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
rails-4.0 | Not in release | Not in release | Not in release | Not in release |
ruby-actionpack-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activemodel-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activerecord-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activesupport-3.2 | Not in release | Not in release | Not in release | Not in release |
rails | Not affected | Not affected | Not affected | Vulnerable |
ruby-rails-3.2 | Not in release | Not in release | Not in release | Not in release |
Some fixes available 2 of 4
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
7 affected packages
rails, rails-4.0, ruby-actionpack-3.2, ruby-activemodel-3.2, ruby-activerecord-3.2...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
rails | Not affected | Not affected | Not affected | Fixed |
rails-4.0 | Not in release | Not in release | Not in release | Not in release |
ruby-actionpack-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activemodel-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activerecord-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-rails-3.2 | Not in release | Not in release | Not in release | Not in release |
ruby-activesupport-3.2 | Not in release | Not in release | Not in release | Not in release |