Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-98mf-8f57-64qf
    Fix available
    Packages

    actionpack, actionpack, actionpack

    Summary

    actionpack Cross-site Scripting vulnerability

    Published
    24 Oct 2017
    GHSA-99ch-8mvp-g7m5
    No fix available
    Packages

    md2pdf

    Summary

    md2pdf allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename

    Published
    24 Oct 2017
    GHSA-9c2j-593q-3g82
    Fix available
    Packages

    activesupport, activesupport

    Summary

    activesupport Improper Input Validation vulnerability

    Published
    24 Oct 2017
    GHSA-9h36-4jf2-hx53
    Fix available
    Packages

    extlib

    Summary

    extlib does not properly restrict casts of string values

    Published
    24 Oct 2017
    GHSA-9hx9-w2j6-rw76
    No fix available
    Packages

    show_in_browser

    Summary

    Script Injection in Show In Browser gem

    Published
    24 Oct 2017
    GHSA-9qj7-jvg4-qr2x
    Fix available
    Packages

    passenger, passenger

    Summary

    Phusion Passenger Denial of Service

    Published
    24 Oct 2017
    GHSA-gppp-5xc5-wfpx
    Fix available
    Packages

    activerecord, activerecord, activerecord

    Summary

    Active Record allows bypassing of database-query restrictions

    Published
    24 Oct 2017
    GHSA-c43v-hrmg-56r4
    Fix available
    Packages

    cocaine

    Summary

    Cocaine Gem OS Command Injection vulnerability

    Published
    24 Oct 2017
    GHSA-cf36-985g-v73c
    Fix available
    Packages

    omniauth-facebook

    Summary

    omniauth-facebook Cross-Site Request Forgery vulnerability

    Published
    24 Oct 2017
    GHSA-cj43-9h3w-v976
    Fix available
    Packages

    puppet, puppet

    Summary

    Puppet allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service

    Published
    24 Oct 2017
    GHSA-f7p5-w2cr-7cp7
    Fix available
    Packages

    puppet, puppet

    Summary

    Puppet Improper Input Validation vulnerability

    Published
    24 Oct 2017
    GHSA-fgmx-8h93-26fh
    Fix available
    Packages

    omniauth-oauth2

    Summary

    omniauth-oauth2 Cross-Site Request Forgery vulnerability

    Published
    24 Oct 2017
    GHSA-fhj9-cjjh-27vm
    Fix available
    Packages

    activerecord, activerecord

    Summary

    Active Record contains deserialization of arbitrary YAML

    Published
    24 Oct 2017
    GHSA-g266-3crh-h7gj
    No fix available
    Packages

    ldoce

    Summary

    ldoce Gem Arbitrary Command Execution

    Published
    24 Oct 2017
    GHSA-g89m-3wjw-h857
    Fix available
    Packages

    puppet, puppet

    Summary

    Puppet vulnerable to Path Traversal

    Published
    24 Oct 2017
    GHSA-gh2w-j7cx-2664
    Fix available
    Packages

    activerecord, activerecord, activerecord, activerecord

    Summary

    Active Record contains SQL Injection

    Published
    24 Oct 2017
    GHSA-gr44-7grc-37vq
    Fix available
    Packages

    activerecord, activerecord, activerecord

    Summary

    ActiveRecord vulnerable to modification of protected model attributes

    Published
    24 Oct 2017
    GHSA-h77x-m5q8-c29h
    Fix available
    Packages

    rack, rack, rack, rack

    Summary

    Rack vulnerable to REDoS

    Published
    24 Oct 2017
    GHSA-h835-75hw-pj89
    Fix available
    Packages

    activesupport, activesupport, activesupport, activesupport

    Summary

    activesupport Cross-site Scripting vulnerability

    Published
    24 Oct 2017
    GHSA-hxx6-p24v-wg8c
    No fix available
    Packages

    curl

    Summary

    Curl Gem insufficient URL escaping command injection

    Published
    24 Oct 2017
    GHSA-j838-vfpq-fmf2
    Fix available
    Packages

    actionpack, actionpack, actionpack

    Summary

    actionpack Cross-site Scripting vulnerability

    Published
    24 Oct 2017
    GHSA-jg4m-q6w8-vrjp
    Fix available
    Packages

    rgpg

    Summary

    rgpg Code Injection vulnerability

    Published
    24 Oct 2017
    GHSA-jmgw-6vjg-jjwg
    Fix available
    Packages

    actionpack, actionpack, actionpack, actionpack

    Summary

    actionpack Improper Input Validation vulnerability

    Published
    24 Oct 2017
    GHSA-jxhw-mg8m-2pj8
    Fix available
    Packages

    devise, devise, devise, devise

    Summary

    Devise does not properly perform type conversion when performing database queries

    Published
    24 Oct 2017
    GHSA-jxx8-v83v-rhw3
    Fix available
    Packages

    spree

    Summary

    Spree Improper Input Validation vulnerability

    Published
    24 Oct 2017
    GHSA-m6f7-46hw-grcj
    Fix available
    Packages

    cremefraiche

    Summary

    Creme Fraiche contains OS Command Injection

    Published
    24 Oct 2017
    GHSA-m7fq-cf8q-35q7
    Fix available
    Packages

    crack

    Summary

    crack does not properly restrict casts of string values

    Published
    24 Oct 2017
    GHSA-mgx3-27hr-mfgp
    Fix available
    Packages

    httparty

    Summary

    HTTParty does not restrict casts of string values

    Published
    24 Oct 2017
    GHSA-mpxf-gcw2-pw5q
    Fix available
    Packages

    actionpack, actionpack

    Summary

    actionpack Improper Input Validation vulnerability

    Published
    24 Oct 2017
    GHSA-p463-639r-q9g9
    Fix available
    Packages

    dragonfly, dragonfly

    Summary

    Dragonfly Code Injection vulnerability

    Published
    24 Oct 2017
    GHSA-p673-hjf2-pwfr
    No fix available
    Packages

    command_wrap

    Summary

    Shell command injection in command_wrap

    Published
    24 Oct 2017
    GHSA-pchc-949f-53m5
    Fix available
    Packages

    multi_xml

    Summary

    Improper Input Validation in multi_xml

    Published
    24 Oct 2017
    GHSA-q44r-f2hm-v76v
    Fix available
    Packages

    puppet, puppet

    Summary

    Pupper does not properly restrict characters in Common Name field of Certificate Signing Request

    Published
    24 Oct 2017
    GHSA-q6cw-2553-7837
    Fix available
    Packages

    newrelic_rpm

    Summary

    newrelic_rpm Gem Discloses Sensitive Information

    Published
    24 Oct 2017
    GHSA-q759-hwvc-m3jg
    Fix available
    Packages

    actionpack, actionpack, actionpack

    Summary

    actionpack Cross-site Scripting vulnerability

    Published
    24 Oct 2017
    GHSA-qqxp-xp9v-vvx6
    Fix available
    Packages

    jquery-ui, jquery-ui-rails, org.webjars.npm:jquery-ui, jQuery.UI.Combined

    Summary

    jquery-ui Tooltip widget vulnerable to XSS

    Published
    24 Oct 2017
    GHSA-qrgf-jqqm-x7xv
    Fix available
    Packages

    dragonfly, fog-dragonfly

    Summary

    Code injection in dragonfly gem

    Published
    24 Oct 2017
    GHSA-r23g-3qw4-gfh2
    Fix available
    Packages

    RedCloth

    Summary

    RedCloth Cross-site Scripting vulnerability

    Published
    24 Oct 2017
    GHSA-r5hc-9xx5-97rw
    Fix available
    Packages

    i18n

    Summary

    i18n gem Cross-site Scripting vulnerability

    Published
    24 Oct 2017
    GHSA-rfmf-rx8w-935w
    Fix available
    Packages

    sounder

    Summary

    Sounder Contains Arbitrary Command Execution Vulnerability

    Published
    24 Oct 2017
    GHSA-rg5m-3fqp-6px8
    Fix available
    Packages

    actionmailer

    Summary

    actionmailer email address processing causes Denial of service

    Published
    24 Oct 2017
    GHSA-rprj-g6xc-p5gq
    Fix available
    Packages

    wicked

    Summary

    Wicked gem contains Path traversal vulnerability

    Published
    24 Oct 2017
    GHSA-v2r9-c84j-v7xm
    Fix available
    Packages

    rdoc

    Summary

    RDoc contains XSS vulnerability

    Published
    24 Oct 2017
    GHSA-w248-xr37-jx8m
    No fix available
    Packages

    fastreader

    Summary

    fastreader Gem for Ruby URI Handling Arbitrary Command Injection

    Published
    24 Oct 2017
    GHSA-w6rc-q387-vpgq
    Fix available
    Packages

    passenger

    Summary

    insecure temporary directory usage in passenger

    Published
    24 Oct 2017
    GHSA-w754-gq8r-pf5f
    Fix available
    Packages

    mini_magick

    Summary

    MiniMagick Gem for Ruby URI Handling Arbitrary Command Injection

    Published
    24 Oct 2017
    GHSA-x457-cw4h-hq5f
    Fix available
    Packages

    json, json, json

    Summary

    JSON gem has Improper Input Validation vulnerability

    Published
    24 Oct 2017
    GHSA-xgr2-v94m-rc9g
    Fix available
    Packages

    activesupport, activesupport

    Summary

    activesupport in Rails vulnerable to incorrect data conversion

    Published
    24 Oct 2017
    GHSA-xxvw-45rp-3mj2
    Fix available
    Packages

    js-yaml

    Summary

    Deserialization Code Execution in js-yaml

    Published
    24 Oct 2017
    GHSA-229r-pqp6-8w6g
    No fix available
    Packages

    sprout

    Summary

    sprout Arbitrary Code Execution vulnerability

    Published
    24 Oct 2017