Rubyonrails
rubyonrails
144 CVEs • 14 products
Products (14)
Click to collapseToggle
Products (14)
Click to collapse
CVEs (144)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rubyonrails 1Active Record Session Store Jun 17, 2026 Mar 5, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The activerecord-session_store (aka Active Record Session Store) component through 1.1.3 for Ruby on Rails does not use a constant-time approach when delivering information about whether a guessed session ID is valid. Co...Show more |
2Fedoraproject Rubyonrails2Fedora RailsJun 17, 2026 Feb 11, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host...Show more |
2Fedoraproject Rubyonrails2Fedora RailsJun 17, 2026 Feb 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` ty...Show more |
In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attac...Show more |
2Fedoraproject Rubyonrails2Fedora RailsJun 17, 2026 Jul 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production. |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jul 2, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF t...Show more |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jul 2, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE. |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jun 19, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains. |
3Debian OpensuseRubyonrails3Debian Linux LeapRailsJun 17, 2026 Jun 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in...Show more |
3Debian OpensuseRubyonrails4Backports Sle Debian LinuxLeap+1 moreJun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters. |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end use...Show more |
2Debian Rubyonrails2Actionpack Page Caching Debian LinuxJun 17, 2026 May 12, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to...Show more |
2Fedoraproject Rubyonrails2Active Resource FedoraJun 17, 2026 May 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information. |
4Debian FedoraprojectOpensuse+1 more4Actionview Debian LinuxFedora+1 moreJun 17, 2026 Mar 19, 2020 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS...Show more |
2Debian Rubyonrails2Debian Linux RailsNov 21, 2024 Nov 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks. |
3Debian FedoraprojectRubyonrails3Debian Linux FedoraRailsJun 17, 2026 Mar 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combinatio...Show more |
5Debian FedoraprojectOpensuse+2 more6Cloudforms Debian LinuxFedora+3 moreJun 17, 2026 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unre...Show more |
5Debian FedoraprojectOpensuse+2 more6Cloudforms Debian LinuxFedora+3 moreJun 17, 2026 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesyste...Show more |
A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify the `content-disposition` and `content-type` parameters which can be used in with HTML files and ha...Show more |
2Redhat Rubyonrails2Cloudforms RailsNov 21, 2024 Nov 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they shoul...Show more |