Actionpack Project Actionpack vulnerabilities

63 known vulnerabilities affecting actionpack_project/actionpack.

Total CVEs
63
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH16MEDIUM42LOW4

Vulnerabilities

Page 3 of 4
CVE-2013-6415MEDIUM≥ 3.0.0, < 3.2.16≥ 4.0.0, < 4.0.22017-10-24
CVE-2013-6415 [MEDIUM] CWE-79 actionpack vulnerable to Cross-site Scripting actionpack vulnerable to Cross-site Scripting Cross-site scripting (XSS) vulnerability in the `number_to_currency` helper in `actionpack/lib/action_view/helpers/number_helper.rb` in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
ghsaosv
CVE-2011-0446MEDIUM≥ 0, < 2.3.11≥ 3.0.0, < 3.0.42017-10-24
CVE-2011-0446 [MEDIUM] CWE-79 Rails actionpack gem vulnerable to Cross-site Scripting Rails actionpack gem vulnerable to Cross-site Scripting Multiple cross-site scripting (XSS) vulnerabilities in the `mail_to` helper in Ruby on Rails before 2.3.11, and 3.x before 3.0.4, when javascript encoding is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) name or (2) email value.
ghsaosv
CVE-2008-7248MEDIUMPoC≥ 2.1.0, < 2.1.3≥ 2.2.0, < 2.2.22017-10-24
CVE-2008-7248 [MEDIUM] CWE-20 Improper Input Validation in actionpack Improper Input Validation in actionpack Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.
ghsaosv
CVE-2013-4491MEDIUM≥ 3.0.0, < 3.2.16≥ 4.0.0, < 4.0.22017-10-24
CVE-2013-4491 [MEDIUM] CWE-79 actionpack vulnerable to Cross-site Scripting actionpack vulnerable to Cross-site Scripting Cross-site scripting (XSS) vulnerability in `actionpack/lib/action_view/helpers/translation_helper.rb` in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
ghsaosv
CVE-2014-0082MEDIUM≥ 3.0.0, < 3.2.172017-10-24
CVE-2014-0082 [MEDIUM] CWE-20 actionpack Improper Input Validation vulnerability actionpack Improper Input Validation vulnerability `actionpack/lib/action_view/template/text.rb` in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the `:text` option to the `render` method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers.
ghsaosv
CVE-2012-2694MEDIUMCVSS 6.4≥ 3.0.13, < 3.0.14≥ 3.1.0, < 3.1.6+1 more2017-10-24
CVE-2012-2694 [MEDIUM] actionpack allows remote attackers to bypass database-query restrictions, perform NULL checks via crafted request actionpack allows remote attackers to bypass database-query restrictions, perform NULL checks via crafted request `actionpack/lib/action_dispatch/http/request.rb` in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, whi
ghsaosv
CVE-2011-4319MEDIUM≥ 3.0.0, < 3.0.11≥ 3.1.0, < 3.1.22017-10-24
CVE-2011-4319 [MEDIUM] CWE-79 Cross-site Scripting vulnerability in i18n translations helper method Cross-site Scripting vulnerability in i18n translations helper method Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with an "html"
ghsaosv
CVE-2011-3187MEDIUMPoC≥ 2.3.0, < 2.3.132017-10-24
CVE-2011-3187 [MEDIUM] CWE-20 actionpack Improper Input Validation vulnerability actionpack Improper Input Validation vulnerability The `to_s` method in `actionpack/lib/action_dispatch/middleware/remote_ip.rb` in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.
ghsaosv
CVE-2013-6416MEDIUM≥ 4.0.0, < 4.0.22017-10-24
CVE-2013-6416 [MEDIUM] CWE-79 actionpack Cross-site Scripting vulnerability actionpack Cross-site Scripting vulnerability Cross-site scripting (XSS) vulnerability in the simple_format helper in `actionpack/lib/action_view/helpers/text_helper.rb` in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.
ghsaosv
CVE-2012-2660MEDIUMCVSS 4.3≥ 3.0.0.beta, < 3.0.13≥ 3.1.0, < 3.1.5+2 more2017-10-24
CVE-2012-2660 [MEDIUM] CWE-284 Action Pack contains database-query restrictions bypass Action Pack contains database-query restrictions bypass `actionpack/lib/action_dispatch/http/request.rb` in Ruby on Rails before 2.3.16, 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which allows remote attackers to bypass intended database-query restrictions and perform N
ghsaosv
CVE-2012-1099MEDIUM≥ 3.0.0, < 3.0.12≥ 3.1.0, < 3.1.4+1 more2017-10-24
CVE-2012-1099 [MEDIUM] CWE-79 Cross-site Scripting in actionpack Cross-site Scripting in actionpack Cross-site scripting (XSS) vulnerability in `actionpack/lib/action_view/helpers/form_options_helper.rb` in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving certain generation of OPTION elements within SELECT elements.
ghsaosv
CVE-2013-6414MEDIUM≥ 3.0.0, < 3.2.16≥ 4.0.0, < 4.0.22017-10-24
CVE-2013-6414 [MEDIUM] CWE-20 actionpack Improper Input Validation vulnerability actionpack Improper Input Validation vulnerability `actionpack/lib/action_view/lookup_context.rb` in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.
ghsaosv
CVE-2013-6417MEDIUMCVSS 6.4≥ 3.0.0, < 3.2.16≥ 4.0.0, < 4.0.22017-10-24
CVE-2013-6417 [MEDIUM] CWE-284 actionpack allows bypass of database-query restrictions actionpack allows bypass of database-query restrictions `actionpack/lib/action_dispatch/http/request.rb` in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE cla
ghsaosv
CVE-2009-3086MEDIUM≥ 2.1.0, < 2.2.3≥ 2.3.0, < 2.3.42017-10-24
CVE-2009-3086 [MEDIUM] CWE-200 actionpack and activesupport vulnerable to information leaks actionpack and activesupport vulnerable to information leaks A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.
ghsaosv
CVE-2014-7829MEDIUMCVSS 4.3≥ 4.1.0, < 4.1.8≥ 3.0.0, < 3.2.21+2 more2017-10-24
CVE-2014-7829 [MEDIUM] CWE-22 Directory traversal vulnerability in actionpack Directory traversal vulnerability in actionpack Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via vectors involving a \ (backslash
ghsaosv
CVE-2013-1855MEDIUM≥ 0, < 2.3.18≥ 3.0.0, < 3.1.12+1 more2017-10-24
CVE-2013-1855 [MEDIUM] CWE-79 actionpack Cross-site Scripting vulnerability actionpack Cross-site Scripting vulnerability The `sanitize_css` method in `lib/action_controller/vendor/html-scanner/html/sanitizer.rb` in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle `\n` (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style S
ghsaosv
CVE-2011-3186MEDIUM≥ 2.3.0, < 2.3.132017-10-24
CVE-2011-3186 [MEDIUM] CWE-94 actionpack CRLF injection vulnerability actionpack CRLF injection vulnerability CRLF injection vulnerability in `actionpack/lib/action_controller/response.rb` in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header.
ghsaosv
CVE-2012-3463MEDIUM≥ 3.0, < 3.0.17≥ 3.1.0, < 3.1.8+1 more2017-10-24
CVE-2012-3463 [MEDIUM] CWE-79 actionpack Cross-site Scripting vulnerability actionpack Cross-site Scripting vulnerability Cross-site scripting (XSS) vulnerability in `actionpack/lib/action_view/helpers/form_tag_helper.rb` in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the `prompt` field to the `select_tag` helper.
ghsaosv
CVE-2011-2931MEDIUM≥ 2.0.0, < 2.3.13≥ 3.0.0, < 3.0.102017-10-24
CVE-2011-2931 [MEDIUM] CWE-79 actionpack Cross-site Scripting vulnerability actionpack Cross-site Scripting vulnerability Cross-site scripting (XSS) vulnerability in the `strip_tags` helper in `actionpack/lib/action_controller/vendor/html-scanner/html/node.rb` in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script or HTML via a tag with an invalid name.
ghsaosv
CVE-2014-0081MEDIUMCVSS 4.3≥ 3.0.0, < 3.2.17≥ 4.0.0, < 4.0.32017-10-24
CVE-2014-0081 [MEDIUM] CWE-79 Rails vulnerable to Cross-site Scripting Rails vulnerable to Cross-site Scripting There is an XSS vulnerability in the `number_to_currency`, `number_to_percentage` and `number_to_human` helpers in Ruby on Rails. This vulnerability has been assigned the CVE identifier CVE-2014-0081. Versions Affected: All. Fixed Versions: 4.1.0.beta2, 4.0.3, 3.2.17. Impact These helpers allows users to nicely format a numeric value. Some of the parameters to the helper (format, ne
ghsaosv
Actionpack Project Actionpack vulnerabilities | cvebase