Rubyonrails

Rails

119 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.35%
  • Veröffentlicht 06.01.2021 21:15:14
  • Zuletzt bearbeitet 21.11.2024 05:38:37

In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in t...

Exploit
  • EPSS 91.07%
  • Veröffentlicht 02.07.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:24

The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.

Exploit
  • EPSS 0.44%
  • Veröffentlicht 02.07.2020 19:15:12
  • Zuletzt bearbeitet 28.04.2026 16:16:05

A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.

  • EPSS 0.68%
  • Veröffentlicht 02.07.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:27

A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.

Exploit
  • EPSS 90.13%
  • Veröffentlicht 19.06.2020 18:15:11
  • Zuletzt bearbeitet 09.05.2025 20:15:36

A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.

Exploit
  • EPSS 0.43%
  • Veröffentlicht 19.06.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 05:38:25

A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.

Exploit
  • EPSS 1.55%
  • Veröffentlicht 19.06.2020 17:15:18
  • Zuletzt bearbeitet 21.11.2024 05:38:24

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

Exploit
  • EPSS 7.39%
  • Veröffentlicht 19.06.2020 17:15:18
  • Zuletzt bearbeitet 21.11.2024 05:38:25

A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 12.11.2019 21:15:10
  • Zuletzt bearbeitet 21.11.2024 01:18:27

The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.

Warnung Exploit
  • EPSS 94.32%
  • Veröffentlicht 27.03.2019 14:29:01
  • Zuletzt bearbeitet 30.10.2025 20:40:11

There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.