cbcvebase.

Debian Rails vulnerabilities

139 known vulnerabilities affecting debian/rails.

Total CVEs
139
CISA KEV
2
actively exploited
Public exploits
13
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH30MEDIUM55LOW47

Vulnerabilities

Page 3 of 7
CVE-2021-22902HIGHCVSS 7.5fixed in rails 2:6.0.3.7+dfsg-1 (bookworm)2021
CVE-2021-22902 [HIGH] CVE-2021-22902: rails - The actionpack ruby gem (a framework for handling and responding to web requests... The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine. Scope:
debian
CVE-2021-22880HIGHCVSS 7.5fixed in rails 2:6.0.3.5+dfsg-1 (bookworm)2021
CVE-2021-22880 [HIGH] CVE-2021-22880: rails - The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers... The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS attack. This only i
debian
CVE-2021-22881MEDIUMCVSS 6.1PoCfixed in rails 2:6.0.3.5+dfsg-1 (bookworm)2021
CVE-2021-22881 [MEDIUM] CVE-2021-22881: rails - The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers... The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. Impacted applications will have allowed hosts with a leading dot.
debian
CVE-2021-22942MEDIUMCVSS 6.1fixed in rails 2:6.1.4.1+dfsg-3 (bookworm)2021
CVE-2021-22942 [MEDIUM] CVE-2021-22942: rails - A possible open redirect vulnerability in the Host Authorization middleware in A... A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website. Scope: local bookworm: resolved (fixed in 2:6.1.4.1+dfsg-3) bullseye: resolved (fixed in 2:6.0.3.7+dfsg-2+deb11u1) forky: resolved (fixed in 2:6.1.4.1+dfsg-3) sid: resolved (fixed in 2:6.1.4.1+dfsg-3
debian
CVE-2021-44528MEDIUMCVSS 6.1PoCfixed in rails 2:6.1.4.6+dfsg-1 (bookworm)2021
CVE-2021-44528 [MEDIUM] CVE-2021-44528: rails - A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an... A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. Scope: local bookworm: resolved (fixed in 2:6.1.4.6+dfsg-1) bullseye: resolved (fixed in
debian
CVE-2021-22903LOWCVSS 6.12021
CVE-2021-22903 [MEDIUM] CVE-2021-22903: rails - The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vul... The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. This is similar to CVE-2021-22881. Strings in config.hosts that do not have a leading dot are
debian
CVE-2020-8165CRITICALCVSS 9.8fixed in rails 2:5.2.4.3+dfsg-1 (bookworm)2020
CVE-2020-8165 [CRITICAL] CVE-2020-8165: rails - A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, ... A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE. Scope: local bookworm: resolved (fixed in 2:5.2.4.3+dfsg-1) bullseye: resolved (fixed in 2:5.2.4.3+dfsg-1) forky: resolved (fixed in 2:5.2.4
debian
CVE-2020-8162HIGHCVSS 7.5fixed in rails 2:5.2.4.3+dfsg-1 (bookworm)2020
CVE-2020-8162 [HIGH] CVE-2020-8162: rails - A client side enforcement of server side security vulnerability exists in rails ... A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits. Scope: local bookworm: resolved (fixed in 2:5.2.4.3+dfsg-1) bullseye: resolved (fixed in 2:5.2.4.3+dfsg-1) forky: resolved (f
debian
CVE-2020-8163HIGHCVSS 8.8PoCfixed in rails 2:5.2.0+dfsg-2 (bookworm)2020
CVE-2020-8163 [HIGH] CVE-2020-8163: rails - The is a code injection vulnerability in versions of Rails prior to 5.0.1 that w... The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE. Scope: local bookworm: resolved (fixed in 2:5.2.0+dfsg-2) bullseye: resolved (fixed in 2:5.2.0+dfsg-2) forky: resolved (fixed in 2:5.2.0+dfsg-2) sid: resolved (fixed in 2:5.2.0+dfsg-2) trixie: res
debian
CVE-2020-8164HIGHCVSS 7.5fixed in rails 2:5.2.4.3+dfsg-1 (bookworm)2020
CVE-2020-8164 [HIGH] CVE-2020-8164: rails - A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rai... A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters. Scope: local bookworm: resolved (fixed in 2:5.2.4.3+dfsg-1) bullseye: resolved (fixed in 2:5.2.4.3+dfsg-1) forky: resolved (fixed in 2:5.2.4.3+dfsg-1) sid: resolved (fixed in 2:5
debian
CVE-2020-8264MEDIUMCVSS 6.1fixed in rails 2:6.0.3.4+dfsg-1 (bookworm)2020
CVE-2020-8264 [MEDIUM] CVE-2020-8264: rails - In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an applicat... In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local application. This vulnerability is in the Actionable Exceptions middleware. Scope: local bookwor
debian
CVE-2020-8166MEDIUMCVSS 4.3fixed in rails 2:5.2.4.3+dfsg-1 (bookworm)2020
CVE-2020-8166 [MEDIUM] CVE-2020-8166: rails - A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes i... A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token. Scope: local bookworm: resolved (fixed in 2:5.2.4.3+dfsg-1) bullseye: resolved (fixed in 2:5.2.4.3+dfsg-1) forky: resolved (fixed in 2:5.2.4.3+d
debian
CVE-2020-15169MEDIUMCVSS 5.4fixed in rails 2:6.0.3.3+dfsg-1 (bookworm)2020
CVE-2020-15169 [MEDIUM] CVE-2020-15169: rails - In Action View before versions 5.2.4.4 and 6.0.3.3 there is a potential Cross-Si... In Action View before versions 5.2.4.4 and 6.0.3.3 there is a potential Cross-Site Scripting (XSS) vulnerability in Action View's translation helpers. Views that allow the user to control the default (not found) value of the `t` and `translate` helpers could be susceptible to XSS attacks. When an HTML-unsafe string is passed as the default for a missing translation
debian
CVE-2020-8167MEDIUMCVSS 6.5fixed in rails 2:5.2.4.3+dfsg-1 (bookworm)2020
CVE-2020-8167 [MEDIUM] CVE-2020-8167: rails - A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow ... A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains. Scope: local bookworm: resolved (fixed in 2:5.2.4.3+dfsg-1) bullseye: resolved (fixed in 2:5.2.4.3+dfsg-1) forky: resolved (fixed in 2:5.2.4.3+dfsg-1) sid: resolved (fixed in 2:5.2.4.3+dfsg-1) trixie: resolved (fixed in 2:5.2.4.3+dfsg-1)
debian
CVE-2020-5267MEDIUMCVSS 4.0fixed in rails 2:5.2.4.1+dfsg-2 (bookworm)2020
CVE-2020-5267 [MEDIUM] CVE-2020-5267: rails - In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulne... In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2. Scope: local bookworm: resolved (fixed in 2:5.2.4.1+dfsg-2) bullseye: resolved (fixed in
debian
CVE-2020-8185LOWCVSS 6.52020
CVE-2020-8185 [MEDIUM] CVE-2020-8185: rails - A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untru... A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2020-8151LOWCVSS 7.52020
CVE-2020-8151 [HIGH] CVE-2020-8151: rails - There is a possible information disclosure issue in Active Resource <v5.1.1 that... There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2019-5420CRITICALCVSS 9.8PoCfixed in rails 2:5.2.2.1+dfsg-1 (bookworm)2019
CVE-2019-5420 [CRITICAL] CVE-2019-5420: rails - A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0... A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit. Scope: local bookworm: resolved (fixed in 2:5.2.2.1+dfsg-1) bullseye: r
debian
CVE-2019-5419HIGHCVSS 7.5fixed in rails 2:5.2.2.1+dfsg-1 (bookworm)2019
CVE-2019-5419 [HIGH] CVE-2019-5419: rails - There is a possible denial of service vulnerability in Action View (Rails) <5.2.... There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive. Scope: local bookworm: resolved (fixed in 2:5.2.2.1+dfsg-1) bullseye: resolved (fixed in 2:5.2.2.1+dfsg-1) forky: resolved (fixed in 2:5.2.2.1
debian
CVE-2019-5418HIGHCVSS 7.5KEVPoCfixed in rails 2:5.2.2.1+dfsg-1 (bookworm)2019
CVE-2019-5418 [HIGH] CVE-2019-5418: rails - There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6... There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed. Scope: local bookworm: resolved (fixed in 2:5.2.2.1+dfsg-1) bullseye: resolved (fixed in 2:5.2.2.1+dfsg-1) forky: resolved (fixed in 2:
debian
Debian Rails vulnerabilities | cvebase