Debian Rails vulnerabilities
97 known vulnerabilities affecting debian/rails.
Total CVEs
97
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL7HIGH29MEDIUM49LOW12
Vulnerabilities
Page 4 of 5
CVE-2020-15169P4MEDIUMCVSS 5.4fixed in rails 2:6.0.3.3+dfsg-1 (bookworm)2020
CVE-2020-15169 [MEDIUM] CVE-2020-15169: rails - In Action View before versions 5.2.4.4 and 6.0.3.3 there is a potential Cross-Si...
In Action View before versions 5.2.4.4 and 6.0.3.3 there is a potential Cross-Site Scripting (XSS) vulnerability in Action View's translation helpers. Views that allow the user to control the default (not found) value of the `t` and `translate` helpers could be susceptible to XSS attacks. When an HTML-unsafe string is passed as the default for a missing translation
debian
CVE-2012-6497P4HIGHCVSS 7.5fixed in rails 2.3.14.1 (bookworm)2012
CVE-2012-6497 [HIGH] CVE-2012-6497: rails - The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2....
The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in secret_token.rb in an open-source prod
debian
CVE-2007-5380P4MEDIUMCVSS 6.8fixed in rails 1.2.5-1 (bookworm)2007
CVE-2007-5380 [MEDIUM] CVE-2007-5380: rails - Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails,...
Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to "URL-based sessions."
Scope: local
bookworm: resolved (fixed in 1.2.5-1)
bullseye: resolved (fixed in 1.2.5-1)
forky: resolved (fixed in 1.2.5-1)
sid: resolved (fixed in 1.2.5-1)
trixie: resolved (fixed in 1
debian
CVE-2014-0082P4MEDIUMCVSS 5.0fixed in rails 2.3.14.1 (bookworm)2014
CVE-2014-0082 [MEDIUM] CVE-2014-0082: rails - actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x ...
actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers.
Scope: local
bookworm: resolved (fixed in 2.3.14.1)
bullseye: reso
debian
CVE-2016-6316P4LOWCVSS 6.1fixed in rails 2:4.2.7.1-1 (bookworm)2016
CVE-2016-6316 [MEDIUM] CVE-2016-6316: rails - Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x bef...
Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.
Scope: local
bookworm: resolved (fixed in 2:4.2.7.1-1)
bullseye: resolved (fixed in 2:
debian
CVE-2022-27777P4MEDIUMCVSS 6.1fixed in rails 2:6.1.6.1+dfsg-1 (bookworm)2022
CVE-2022-27777 [MEDIUM] CVE-2022-27777: rails - A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would ...
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes.
Scope: local
bookworm: resolved (fixed in 2:6.1.6.1+dfsg-1)
bullseye: resolved (fixed in 2:6.0.3.7+dfsg-2+deb11u1)
forky: resolved (fixed in 2:6.1.6.1+dfsg-1)
sid: resolved (fixed in 2:6.1.6.1+dfsg-1)
debian
CVE-2014-7818P4MEDIUMCVSS 4.3fixed in rails 2:4.1.8-1 (bookworm)2014
CVE-2014-7818 [MEDIUM] CVE-2014-7818: rails - Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/s...
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via a /..%2F sequence.
Scope: loc
debian
CVE-2013-0276P4MEDIUMCVSS 4.3fixed in rails 2.3.14.1 (bookworm)2013
CVE-2013-0276 [MEDIUM] CVE-2013-0276: rails - ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x befo...
ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.
Scope: local
bookworm: resolved (fixed in 2.3.14.1)
bullseye: resolved (fixed in 2.3.14.1)
forky: resolved (fixed in 2.3.14.1)
sid: resolved (fix
debian
CVE-2011-0447P4MEDIUMCVSS 6.8fixed in rails 2.3.11-0.1 (bookworm)2011
CVE-2011-0447 [MEDIUM] CVE-2011-0447: rails - Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3.0.4, does ...
Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3.0.4, does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged (1) AJAX or (2) API requests that leverage "combinations of browser plugins and HTTP redirects," a related
debian
CVE-2021-22942P4MEDIUMCVSS 6.1fixed in rails 2:6.1.4.1+dfsg-3 (bookworm)2021
CVE-2021-22942 [MEDIUM] CVE-2021-22942: rails - A possible open redirect vulnerability in the Host Authorization middleware in A...
A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.
Scope: local
bookworm: resolved (fixed in 2:6.1.4.1+dfsg-3)
bullseye: resolved (fixed in 2:6.0.3.7+dfsg-2+deb11u1)
forky: resolved (fixed in 2:6.1.4.1+dfsg-3)
sid: resolved (fixed in 2:6.1.4.1+dfsg-3
debian
CVE-2024-26144P4MEDIUMCVSS 5.3fixed in rails 2:6.1.7.10+dfsg-1~deb12u1 (bookworm)2024
CVE-2024-26144 [MEDIUM] CVE-2024-26144: rails - Rails is a web-application framework. Starting with version 5.2.0, there is a po...
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak. The v
debian
CVE-2023-38037P4MEDIUMCVSS 5.5fixed in rails 2:6.1.7.10+dfsg-1~deb12u1 (bookworm)2023
CVE-2023-38037 [MEDIUM] CVE-2023-38037: rails - ActiveSupport::EncryptedFile writes contents that will be encrypted to a
tempor...
ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user's current `umask` settings, meaning that it's possible for other users on the same system to read the contents of the temporary file. Attackers that have access to the file system could possibly read the contents of this
debian
CVE-2023-28120P4MEDIUMCVSS 5.3fixed in rails 2:6.1.7.3+dfsg-1 (bookworm)2023
CVE-2023-28120 [MEDIUM] CVE-2023-28120: rails - There is a vulnerability in ActiveSupport if the new bytesplice method is called...
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
Scope: local
bookworm: resolved (fixed in 2:6.1.7.3+dfsg-1)
bullseye: resolved (fixed in 2:6.0.3.7+dfsg-2+deb11u2)
forky: resolved (fixed in 2:6.1.7.3+dfsg-1)
sid: resolved (fixed in 2:6.1.7.3+dfsg-1)
trixie: resolved (fixed in 2:6.1.7.3+dfsg-1
debian
CVE-2007-6077P4LOWCVSS 6.8fixed in rails 1.2.6-1 (bookworm)2007
CVE-2007-6077 [MEDIUM] CVE-2007-6077: rails - The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as u...
The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks. NOTE: this is due to an i
debian
CVE-2015-3227P4MEDIUMCVSS 5.0fixed in rails 2:4.2.4-2 (bookworm)2015
CVE-2015-3227 [MEDIUM] CVE-2015-3227: rails - The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails b...
The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.
Scope: local
bookworm: resolved (fixed in 2:4.2.4-2)
bullseye: resolved (fixed in 2:4.2.4-2)
forky: resolved (fixed in
debian
CVE-2013-1854P4MEDIUMCVSS 5.0fixed in rails 2.3.14.1 (bookworm)2013
CVE-2013-1854 [MEDIUM] CVE-2013-1854: rails - The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3...
The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.
Scope: local
bookworm: resolved (fixed in 2.3.14.1)
bullseye: resolved (fixed in 2.3.14.1)
forky: res
debian
CVE-2008-5189P4LOWCVSS 5.0fixed in rails 2.1.0-6 (bookworm)2008
CVE-2008-5189 [MEDIUM] CVE-2008-5189: rails - CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attacke...
CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.
Scope: local
bookworm: resolved (fixed in 2.1.0-6)
bullseye: resolved (fixed in 2.1.0-6)
forky: resolved (fixed in 2.1.0-6)
sid: resolved (fixed in 2.1.0-6)
trixie
debian
CVE-2011-3186P4MEDIUMCVSS 4.3fixed in rails 2.3.14 (bookworm)2011
CVE-2011-3186 [MEDIUM] CVE-2011-3186: rails - CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in ...
CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header.
Scope: local
bookworm: resolved (fixed in 2.3.14)
bullseye: resolved (fixed in 2.3.14)
forky: resolved (fixed in 2.3.14)
sid:
debian
CVE-2014-0081P4MEDIUMCVSS 4.3fixed in rails 2.3.14.1 (bookworm)2014
CVE-2014-0081 [MEDIUM] CVE-2014-0081: rails - Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_vie...
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to the (a) number_to_currency, (b) number_to_percentage,
debian
CVE-2009-3086P4LOWCVSS 5.0fixed in rails 2.2.3-1 (bookworm)2009
CVE-2009-3086 [MEDIUM] CVE-2009-3086: rails - A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4...
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.
Scope: local
bookworm: resolved (fixed in 2.2.3-1)
bullseye: resolved (fixed in 2.2.3-1)
forky: resolved (fixed
debian