Show filters
159 Total Results
Displaying 61-70 of 159
Sort by:
Attacker Value
Unknown

CVE-2020-8162

Disclosure Date: June 19, 2020 (last updated February 21, 2025)
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.
Attacker Value
Unknown

CVE-2010-3299

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
Attacker Value
Unknown

CVE-2019-12728

Disclosure Date: June 04, 2019 (last updated November 27, 2024)
Grails before 3.3.10 used cleartext HTTP to resolve the SDKMan notification service. NOTE: users' apps were not resolving dependencies over cleartext HTTP.
Attacker Value
Unknown

CVE-2019-5418

Disclosure Date: March 27, 2019 (last updated October 06, 2023)
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
Attacker Value
Unknown

CVE-2019-5420

Disclosure Date: March 27, 2019 (last updated November 08, 2023)
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.
Attacker Value
Unknown

CVE-2019-5419

Disclosure Date: March 27, 2019 (last updated November 08, 2023)
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.
Attacker Value
Unknown

CVE-2018-16476

Disclosure Date: November 30, 2018 (last updated November 27, 2024)
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.
0
Attacker Value
Unknown

CVE-2018-16477

Disclosure Date: November 30, 2018 (last updated November 27, 2024)
A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify the `content-disposition` and `content-type` parameters which can be used in with HTML files and have them executed inline. Additionally, if combined with other techniques such as cookie bombing and specially crafted AppCache manifests, an attacker can gain access to private signed URLs within a specific storage path. This vulnerability has been fixed in version 5.2.1.1.
0
Attacker Value
Unknown

CVE-2018-18476

Disclosure Date: October 24, 2018 (last updated November 27, 2024)
mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected database columns.
0
Attacker Value
Unknown

CVE-2016-10522

Disclosure Date: July 05, 2018 (last updated November 27, 2024)
rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.
0