Actionpack Project Actionpack vulnerabilities
63 known vulnerabilities affecting actionpack_project/actionpack.
Total CVEs
63
CISA KEV
2
actively exploited
Public exploits
8
Exploited in wild
3
Severity breakdown
CRITICAL1HIGH16MEDIUM42LOW4
Vulnerabilities
Page 4 of 4
CVE-2012-3463P4MEDIUM≥ 3.0, < 3.0.17≥ 3.1.0, < 3.1.8+1 more2017-10-24
CVE-2012-3463 [MEDIUM] CWE-79 actionpack Cross-site Scripting vulnerability
actionpack Cross-site Scripting vulnerability
Cross-site scripting (XSS) vulnerability in `actionpack/lib/action_view/helpers/form_tag_helper.rb` in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the `prompt` field to the `select_tag` helper.
ghsaosv
CVE-2023-28362P4MEDIUMCVSS 4.0≥ 0, < 6.1.7.4≥ 7.0.0, < 7.0.5.12023-06-29
CVE-2023-28362 [MEDIUM] CWE-116 Actionpack has possible cross-site scripting vulnerability via User Supplied Values to redirect_to
Actionpack has possible cross-site scripting vulnerability via User Supplied Values to redirect_to
The `redirect_to` method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location heade
ghsaosv
CVE-2024-54133P4LOW≥ 5.2.0, < 7.0.8.7≥ 7.1.0, < 7.1.5.1+2 more2024-12-10
CVE-2024-54133 [LOW] CWE-79 Possible Content Security Policy bypass in Action Dispatch
Possible Content Security Policy bypass in Action Dispatch
There is a possible Cross Site Scripting (XSS) vulnerability in the `content_security_policy` helper in Action Pack.
Impact
Applications which set Content-Security-Policy (CSP) headers dynamically from untrusted user input may be vulnerable to carefully crafted inputs being able to inject new directives into the CSP. This could lead to a bypass of th
ghsaosv
← Previous4 / 4