Search CVE reports


Toggle filters

121 – 130 of 151 results


CVE-2012-3424

Medium priority
Ignored

The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which...

3 affected packages

rails, ruby-rails-2.3, ruby-rails-3.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
ruby-rails-2.3 Not in release
ruby-rails-3.2 Not in release
Show less packages

CVE-2012-2661

Medium priority
Not affected

The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote...

2 affected packages

rails, ruby-rails-2.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
ruby-rails-2.3
Show less packages

CVE-2012-2660

Low priority
Ignored

actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider differences in parameter handling between the Active Record component and the...

2 affected packages

rails, ruby-rails-2.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
ruby-rails-2.3
Show less packages

CVE-2012-1099

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper.rb in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to...

2 affected packages

rails, ruby-rails-2.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
ruby-rails-2.3
Show less packages

CVE-2012-1098

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object...

2 affected packages

ruby-rails-2.3, rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rails-2.3
rails
Show less packages

CVE-2011-4319

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to...

2 affected packages

rails, ruby-actionpack-2.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
ruby-actionpack-2.3
Show less packages

CVE-2011-3187

Low priority
Ignored

The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2011-3186

Medium priority

Some fixes available 3 of 4

CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2011-2932

Medium priority

Some fixes available 3 of 4

Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails 2.x before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2011-2931

Medium priority

Some fixes available 3 of 4

Cross-site scripting (XSS) vulnerability in the strip_tags helper in actionpack/lib/action_controller/vendor/html-scanner/html/node.rb in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages