CVEs (117)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6. |
A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website. |
The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression. I...Show more |
The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in...Show more |
The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Caref...Show more |
2Debian Rubyonrails3Actionpack Page Caching Debian LinuxRailsJun 17, 2026 May 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input. |
2Fedoraproject Rubyonrails2Fedora RailsJun 17, 2026 Feb 11, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host...Show more |
2Fedoraproject Rubyonrails2Fedora RailsJun 17, 2026 Feb 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` ty...Show more |
In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attac...Show more |
2Fedoraproject Rubyonrails2Fedora RailsJun 17, 2026 Jul 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production. |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jul 2, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF t...Show more |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jul 2, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE. |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jun 19, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains. |
3Debian OpensuseRubyonrails3Debian Linux LeapRailsJun 17, 2026 Jun 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in...Show more |
3Debian OpensuseRubyonrails4Backports Sle Debian LinuxLeap+1 moreJun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters. |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end use...Show more |
2Debian Rubyonrails2Debian Linux RailsNov 21, 2024 Nov 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks. |
3Debian FedoraprojectRubyonrails3Debian Linux FedoraRailsJun 17, 2026 Mar 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combinatio...Show more |
5Debian FedoraprojectOpensuse+2 more6Cloudforms Debian LinuxFedora+3 moreJun 17, 2026 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unre...Show more |
5Debian FedoraprojectOpensuse+2 more6Cloudforms Debian LinuxFedora+3 moreJun 17, 2026 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesyste...Show more |