Debian Rails vulnerabilities
97 known vulnerabilities affecting debian/rails.
Total CVEs
97
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL7HIGH29MEDIUM49LOW12
Vulnerabilities
Page 2 of 5
CVE-2014-3483P3HIGHCVSS 7.5fixed in rails 2:4.1.4-1 (bookworm)2014
CVE-2014-3483 [HIGH] CVE-2014-3483: rails - SQL injection vulnerability in activerecord/lib/active_record/connection_adapter...
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.
Scope: local
bookworm: resolved (fixed in 2:4.1.4-1)
bullseye: resolved
debian
CVE-2024-28103P3MEDIUMCVSS 5.4fixed in rails 2:6.1.7.10+dfsg-1~deb12u1 (bookworm)2024
CVE-2024-28103 [MEDIUM] CVE-2024-28103: rails - Action Pack is a framework for handling and responding to web requests. Since 6....
Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in 6.1.7.8, 7.0.8.2, and 7.1.3.3.
Scope: local
bookworm: resolved (fixed in 2:6.1.7.10+dfsg-1~deb12u1)
bullseye: resolved
forky: resolved (fixed
debian
CVE-2020-8162P3HIGHCVSS 7.5fixed in rails 2:5.2.4.3+dfsg-1 (bookworm)2020
CVE-2020-8162 [HIGH] CVE-2020-8162: rails - A client side enforcement of server side security vulnerability exists in rails ...
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.
Scope: local
bookworm: resolved (fixed in 2:5.2.4.3+dfsg-1)
bullseye: resolved (fixed in 2:5.2.4.3+dfsg-1)
forky: resolved (f
debian
CVE-2011-2930P3HIGHCVSS 7.5fixed in rails 2.3.14 (bookworm)2011
CVE-2011-2930 [HIGH] CVE-2011-2930: rails - Multiple SQL injection vulnerabilities in the quote_table_name method in the Act...
Multiple SQL injection vulnerabilities in the quote_table_name method in the ActiveRecord adapters in activerecord/lib/active_record/connection_adapters/ in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allow remote attackers to execute arbitrary SQL commands via a crafted column name.
Scope: local
bookworm: resolved (fixed in 2.3.14)
bull
debian
CVE-2016-6317P3MEDIUMCVSS 6.4fixed in rails 2:4.2.7.1-1 (bookworm)2016
CVE-2016-6317 [MEDIUM] CVE-2016-6317: rails - Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider d...
Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]"
debian
CVE-2021-22904P3HIGHCVSS 7.5fixed in rails 2:6.0.3.7+dfsg-1 (bookworm)2021
CVE-2021-22904 [HIGH] CVE-2021-22904: rails - The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a p...
The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression. Impacted code uses `authenticate_or_request_with_http_token` or `authenticate_with_http_token` for request authentication.
Scope: local
bookworm: resol
debian
CVE-2016-0751P3HIGHCVSS 7.5fixed in rails 2:4.2.5.1-1 (bookworm)2016
CVE-2016-0751 [HIGH] CVE-2016-0751: rails - actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails...
actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP Accept header.
Scope: local
bookworm
debian
CVE-2019-5419P3HIGHCVSS 7.5fixed in rails 2:5.2.2.1+dfsg-1 (bookworm)2019
CVE-2019-5419 [HIGH] CVE-2019-5419: rails - There is a possible denial of service vulnerability in Action View (Rails) <5.2....
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.
Scope: local
bookworm: resolved (fixed in 2:5.2.2.1+dfsg-1)
bullseye: resolved (fixed in 2:5.2.2.1+dfsg-1)
forky: resolved (fixed in 2:5.2.2.1
debian
CVE-2018-16476P3HIGHCVSS 7.5fixed in rails 2:5.2.2+dfsg-1 (bookworm)2018
CVE-2018-16476 [HIGH] CVE-2018-16476: rails - A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an ...
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.
Scope: local
bookworm: resolved (fixed in 2:5.2.2+dfs
debian
CVE-2020-8164P3HIGHCVSS 7.5fixed in rails 2:5.2.4.3+dfsg-1 (bookworm)2020
CVE-2020-8164 [HIGH] CVE-2020-8164: rails - A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rai...
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
Scope: local
bookworm: resolved (fixed in 2:5.2.4.3+dfsg-1)
bullseye: resolved (fixed in 2:5.2.4.3+dfsg-1)
forky: resolved (fixed in 2:5.2.4.3+dfsg-1)
sid: resolved (fixed in 2:5
debian
CVE-2021-22885P3HIGHCVSS 7.5fixed in rails 2:6.0.3.7+dfsg-1 (bookworm)2021
CVE-2021-22885 [HIGH] CVE-2021-22885: rails - A possible information disclosure / unintended method execution vulnerability in...
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
Scope: local
bookworm: resolved (fixed in 2:6.0.3.7+dfsg-1)
bullseye: resolved (fixed in 2:6.0.3.7+dfsg-1)
forky: resolved (fixed in 2:6.0.3.7+dfsg-1)
sid: resolved (fixed in 2:6.0.3.7+
debian
CVE-2008-4094P3MEDIUMCVSS 7.5fixed in rails 2.1.0-1 (bookworm)2008
CVE-2008-4094 [HIGH] CVE-2008-4094: rails - Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remot...
Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.
Scope: local
bookworm: resolved (fixed in 2.1.0-1)
bullseye: resolved (fixed in 2.1.0-1)
forky: resolved (fixed i
debian
CVE-2023-22792P3HIGHCVSS 7.5fixed in rails 2:6.1.7.3+dfsg-1 (bookworm)2023
CVE-2023-22792 [HIGH] CVE-2023-22792: rails - A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7...
A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cookies, in combination with a specially crafted X_FORWARDED_HOST header can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large amounts of CPU and memory, leading to a possible DoS v
debian
CVE-2021-22880P3HIGHCVSS 7.5fixed in rails 2:6.0.3.5+dfsg-1 (bookworm)2021
CVE-2021-22880 [HIGH] CVE-2021-22880: rails - The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers...
The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS attack. This only i
debian
CVE-2014-3514P3HIGHCVSS 7.5fixed in rails 2:4.1.5-1 (bookworm)2014
CVE-2014-3514 [HIGH] CVE-2014-3514: rails - activerecord/lib/active_record/relation/query_methods.rb in Active Record in Rub...
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
Scope: local
bookworm: resolved (fixed in 2:4.1.5-1)
bullseye: resolved (fixed in 2:4.1.5-1)
for
debian
CVE-2023-22795P3HIGHCVSS 7.5fixed in rails 2:6.1.7.3+dfsg-1 (bookworm)2023
CVE-2023-22795 [HIGH] CVE-2023-22795: rails - A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7....
A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP If-None-Match header can cause the regular expression engine to enter a state of catastrophic backtracking, when on a version of Ruby below 3.2.0. This can cause the process to use large amounts of CPU and memory, leading
debian
CVE-2007-3227P4MEDIUMCVSS 4.3PoCfixed in rails 1.2.5-1 (bookworm)2007
CVE-2007-3227 [MEDIUM] CVE-2007-3227: rails - Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_j...
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.
Scope: local
bookworm: resolved (fixed in 1.2.5-1)
bullseye: resolved (fixed in 1.2.5-1)
forky: resolved (fixed in 1.2.5-1)
sid: resolved (fixed in 1.2.5-1)
trixie:
debian
CVE-2013-0155P3MEDIUMCVSS 6.4fixed in rails 2.3.14.1 (bookworm)2013
CVE-2013-0155 [MEDIUM] CVE-2013-0155: rails - Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 ...
Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demo
debian
CVE-2024-47887P3MEDIUMCVSS 6.6fixed in rails 2:6.1.7.10+dfsg-1~deb12u1 (bookworm)2024
CVE-2024-47887 [MEDIUM] CVE-2024-47887: rails - Action Pack is a framework for handling and responding to web requests. Starting...
Action Pack is a framework for handling and responding to web requests. Starting in version 4.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in Action Controller's HTTP Token authentication. For applications using HTTP Token authentication via `authenticate_or_request_with_http_token` or similar, a carefully
debian
CVE-2023-22796P3HIGHCVSS 7.5fixed in rails 2:6.1.7.3+dfsg-1 (bookworm)2023
CVE-2023-22796 [HIGH] CVE-2023-22796: rails - A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0...
A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large amounts of CPU and memory, leading to a possible DoS vulnerability.
Scope: local
bookworm: resolve
debian