Debian Rails vulnerabilities
97 known vulnerabilities affecting debian/rails.
Total CVEs
97
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL7HIGH29MEDIUM49LOW12
Vulnerabilities
Page 3 of 5
CVE-2016-0753P3MEDIUMCVSS 5.3fixed in rails 2:4.2.5.1-1 (bookworm)2016
CVE-2016-0753 [MEDIUM] CVE-2016-0753: rails - Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5...
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
Scope: local
bookworm: resolved (fixed in 2:4.2.5.1-1)
bullseye: resolved (fixed in 2:4.2.5.1-1)
forky: resolved
debian
CVE-2021-22902P3HIGHCVSS 7.5fixed in rails 2:6.0.3.7+dfsg-1 (bookworm)2021
CVE-2021-22902 [HIGH] CVE-2021-22902: rails - The actionpack ruby gem (a framework for handling and responding to web requests...
The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.
Scope:
debian
CVE-2015-7581P3HIGHCVSS 7.5fixed in rails 2:4.2.5.1-1 (bookworm)2015
CVE-2015-7581 [HIGH] CVE-2015-7581: rails - actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Ra...
actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote attackers to cause a denial of service (superfluous caching and memory consumption) by leveraging an application's use of a wildcard controller route.
Scope: local
bookworm: resolved (fixed in 2:4.2.5.1-1)
bullseye: resolved (
debian
CVE-2022-44566P3HIGHCVSS 7.5fixed in rails 2:6.1.7.3+dfsg-1 (bookworm)2022
CVE-2022-44566 [HIGH] CVE-2022-44566: rails - A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <...
A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outside the range for a 64bit signed integer is provided to the PostgreSQL connection adapter, it will treat the target column type as numeric. Comparing integer values against numeric values can result in a slow sequential scan resulting in potential Den
debian
CVE-2024-41128P3MEDIUMCVSS 6.6fixed in rails 2:6.1.7.10+dfsg-1~deb12u1 (bookworm)2024
CVE-2024-41128 [MEDIUM] CVE-2024-41128: rails - Action Pack is a framework for handling and responding to web requests. Starting...
Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the query parameter filtering routines of Action Dispatch. Carefully crafted query parameters can cause query parameter filtering to take an unexpected amount of tim
debian
CVE-2024-47888P3MEDIUMCVSS 6.6fixed in rails 2:6.1.7.10+dfsg-1~deb12u1 (bookworm)2024
CVE-2024-47888 [MEDIUM] CVE-2024-47888: rails - Action Text brings rich text content and editing to Rails. Starting in version 6...
Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the `plain_text_for_blockquote_node helper` in Action Text. Carefully crafted text can cause the `plain_text_for_blockquote_node` helper to take an unexpected amount of time, pos
debian
CVE-2024-47889P3MEDIUMCVSS 6.6fixed in rails 2:6.1.7.10+dfsg-1~deb12u1 (bookworm)2024
CVE-2024-47889 [MEDIUM] CVE-2024-47889: rails - Action Mailer is a framework for designing email service layers. Starting in ver...
Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the block_format helper in Action Mailer. Carefully crafted text can cause the block_format helper to take an unexpected amount of time, possibly resulting in a DoS vulnera
debian
CVE-2015-7577P3MEDIUMCVSS 5.3fixed in rails 2:4.2.5.1-1 (bookworm)2015
CVE-2015-7577 [MEDIUM] CVE-2015-7577: rails - activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on ...
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes f
debian
CVE-2016-2097P4HIGHCVSS 7.5fixed in rails 2:4.2.5.2-1 (bookworm)2016
CVE-2016-2097 [HIGH] CVE-2016-2097: rails - Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22....
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0752.
Scope: local
bookworm: re
debian
CVE-2006-4112P4MEDIUMCVSS 7.5fixed in rails 1.1.6-1 (bookworm)2006
CVE-2006-4112 [HIGH] CVE-2006-4112: rails - Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Ra...
Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than CVE-2006-4111.
Scope: local
bookworm: resolved (fixe
debian
CVE-2018-16477P4MEDIUMCVSS 6.5fixed in rails 2:5.2.2+dfsg-1 (bookworm)2018
CVE-2018-16477 [MEDIUM] CVE-2018-16477: rails - A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and D...
A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify the `content-disposition` and `content-type` parameters which can be used in with HTML files and have them executed inline. Additionally, if combined with other techniques such as cookie bombing and specially crafted AppCache manifests, an attacke
debian
CVE-2006-4111P4MEDIUMCVSS 7.5fixed in rails 1.1.5-1 (bookworm)2006
CVE-2006-4111 [HIGH] CVE-2006-4111: rails - Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "se...
Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.
Scope: local
bookworm: resolved (fixed in 1.1.5-1)
bullseye: resolved (fixed in 1.1.5-1)
forky: resolved (fixed in 1.1.5-1)
sid: resolve
debian
CVE-2022-23633P4HIGHCVSS 7.4fixed in rails 2:6.1.4.6+dfsg-1 (bookworm)2022
CVE-2022-23633 [HIGH] CVE-2022-23633: rails - Action Pack is a framework for handling and responding to web requests. Under ce...
Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails
debian
CVE-2023-23913P4MEDIUMCVSS 6.3fixed in rails 2:6.1.7.3+dfsg-1 (bookworm)2023
CVE-2023-23913 [MEDIUM] CVE-2023-23913: rails - There is a potential DOM based cross-site scripting issue in rails-ujs which lev...
There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.
Scope: local
bookworm: resolve
debian
CVE-2014-7829P4MEDIUMCVSS 4.3fixed in rails 2:4.1.8-1 (bookworm)2014
CVE-2014-7829 [MEDIUM] CVE-2014-7829: rails - Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/s...
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via vectors involving a \ (backsl
debian
CVE-2013-3221P4LOWCVSS 6.4fixed in rails 2.3.14.1 (bookworm)2013
CVE-2013-3221 [MEDIUM] CVE-2013-3221: rails - The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does...
The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated
debian
CVE-2020-8167P4MEDIUMCVSS 6.5fixed in rails 2:5.2.4.3+dfsg-1 (bookworm)2020
CVE-2020-8167 [MEDIUM] CVE-2020-8167: rails - A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow ...
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
Scope: local
bookworm: resolved (fixed in 2:5.2.4.3+dfsg-1)
bullseye: resolved (fixed in 2:5.2.4.3+dfsg-1)
forky: resolved (fixed in 2:5.2.4.3+dfsg-1)
sid: resolved (fixed in 2:5.2.4.3+dfsg-1)
trixie: resolved (fixed in 2:5.2.4.3+dfsg-1)
debian
CVE-2015-7576P4LOWCVSS 3.7fixed in rails 2:4.2.5.1-1 (bookworm)2015
CVE-2015-7576 [LOW] CVE-2015-7576: rails - The http_basic_authenticate_with method in actionpack/lib/action_controller/meta...
The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easie
debian
CVE-2022-22577P4MEDIUMCVSS 6.1fixed in rails 2:6.1.6.1+dfsg-1 (bookworm)2022
CVE-2022-22577 [MEDIUM] CVE-2022-22577: rails - An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an att...
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.
Scope: local
bookworm: resolved (fixed in 2:6.1.6.1+dfsg-1)
bullseye: resolved (fixed in 2:6.0.3.7+dfsg-2+deb11u1)
forky: resolved (fixed in 2:6.1.6.1+dfsg-1)
sid: resolved (fixed in 2:6.1.6.1+dfsg-1)
trixie: resolved (fixed in 2:6.1.6.1+d
debian
CVE-2007-5379P4MEDIUMCVSS 5.0fixed in rails 1.2.5-1 (bookworm)2007
CVE-2007-5379 [MEDIUM] CVE-2007-5379: rails - Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and Activ...
Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via the Hash.from_xml (Hash#from_xml) method, which uses XmlSimple (XML::Simple) unsafely, as demonstrated by reading passwords from the Pidgin (Gaim) .purple/accounts.xml file.
Scope: local
bookwo
debian