cbcvebase.

Debian Rails vulnerabilities

97 known vulnerabilities affecting debian/rails.

Total CVEs
97
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL7HIGH29MEDIUM49LOW12

Vulnerabilities

Page 5 of 5
CVE-2020-5267P4MEDIUMCVSS 4.0fixed in rails 2:5.2.4.1+dfsg-2 (bookworm)2020
CVE-2020-5267 [MEDIUM] CVE-2020-5267: rails - In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulne... In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2. Scope: local bookworm: resolved (fixed in 2:5.2.4.1+dfsg-2) bullseye: resolved (fixed in
debian
CVE-2015-3226P4MEDIUMCVSS 4.3fixed in rails 2:4.2.4-2 (bookworm)2015
CVE-2015-3226 [MEDIUM] CVE-2015-3226: rails - Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support i... Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding. Scope: local bookworm: resolved (fixed in 2:4.2.4-2) bullseye: resolved (fixed in 2:4.2.4-2) forky:
debian
CVE-2013-1855P4MEDIUMCVSS 4.3fixed in rails 2.3.14.1 (bookworm)2013
CVE-2013-1855 [MEDIUM] CVE-2013-1855: rails - The sanitize_css method in lib/action_controller/vendor/html-scanner/html/saniti... The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style
debian
CVE-2013-1857P4MEDIUMCVSS 4.3fixed in rails 2.3.14.1 (bookworm)2013
CVE-2013-1857 [MEDIUM] CVE-2013-1857: rails - The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.... The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted schem
debian
CVE-2020-8166P4MEDIUMCVSS 4.3fixed in rails 2:5.2.4.3+dfsg-1 (bookworm)2020
CVE-2020-8166 [MEDIUM] CVE-2020-8166: rails - A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes i... A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token. Scope: local bookworm: resolved (fixed in 2:5.2.4.3+dfsg-1) bullseye: resolved (fixed in 2:5.2.4.3+dfsg-1) forky: resolved (fixed in 2:5.2.4.3+d
debian
CVE-2009-3009P4LOWCVSS 4.3fixed in rails 2.2.3-1 (bookworm)2009
CVE-2009-3009 [MEDIUM] CVE-2009-3009: rails - Cross-site scripting (XSS) vulnerability in Ruby on Rails 2.x before 2.2.3, and ... Cross-site scripting (XSS) vulnerability in Ruby on Rails 2.x before 2.2.3, and 2.3.x before 2.3.4, allows remote attackers to inject arbitrary web script or HTML by placing malformed Unicode strings into a form helper. Scope: local bookworm: resolved (fixed in 2.2.3-1) bullseye: resolved (fixed in 2.2.3-1) forky: resolved (fixed in 2.2.3-1) sid: resolved (fixed in 2.
debian
CVE-2009-4214P4LOWCVSS 4.3fixed in rails 2.2.3-2 (bookworm)2009
CVE-2009-4214 [MEDIUM] CVE-2009-4214: rails - Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on R... Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb. Scope: local bookworm: resolved (
debian
CVE-2012-1099P4MEDIUMCVSS 4.3fixed in rails 2.3.14 (bookworm)2012
CVE-2012-1099 [MEDIUM] CVE-2012-1099: rails - Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/f... Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper.rb in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving certain generation of OPTION elements within SELECT elements. Scope: local bookwo
debian
CVE-2012-3464P4LOWCVSS 4.3fixed in rails 2.3.14.1 (bookworm)2012
CVE-2012-3464 [MEDIUM] CVE-2012-3464: rails - Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/cor... Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HTML via vectors involving a ' (quote) character. Scope: local bookworm: resolved (fixed in 2.3.14.1) bullseye: resolved (
debian
CVE-2011-2932P4MEDIUMCVSS 4.3fixed in rails 2.3.14 (bookworm)2011
CVE-2011-2932 [MEDIUM] CVE-2011-2932: rails - Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/cor... Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails 2.x before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script or HTML via a malformed Unicode string, related to a "UTF-8 escaping vulnerability." Scope: local bookworm: resolved (fix
debian
CVE-2011-2931P4MEDIUMCVSS 4.3fixed in rails 2.3.14 (bookworm)2011
CVE-2011-2931 [MEDIUM] CVE-2011-2931: rails - Cross-site scripting (XSS) vulnerability in the strip_tags helper in actionpack/... Cross-site scripting (XSS) vulnerability in the strip_tags helper in actionpack/lib/action_controller/vendor/html-scanner/html/node.rb in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script or HTML via a tag with an invalid name. Scope: local bookworm: resolved (fixed in 2.3.14) bullseye:
debian
CVE-2012-1098P4MEDIUMCVSS 4.3fixed in rails 2.3.14 (bookworm)2012
CVE-2012-1098 [MEDIUM] CVE-2012-1098: rails - Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3... Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated through certain methods. Scope: local bookworm: resolved (fixed in 2.3.14) bullseye: resolved (fixed in 2.3.14) forky: reso
debian
CVE-2012-3465P4LOWCVSS 4.3fixed in rails 2.3.14.1 (bookworm)2012
CVE-2012-3465 [MEDIUM] CVE-2012-3465: rails - Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/s... Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup. Scope: local bookworm: resolved (fixed in 2.3.14.1) bullseye: resolved (fixed in 2
debian
CVE-2011-0446P4MEDIUMCVSS 4.3fixed in rails 2.3.11-0.1 (bookworm)2011
CVE-2011-0446 [MEDIUM] CVE-2011-0446: rails - Multiple cross-site scripting (XSS) vulnerabilities in the mail_to helper in Rub... Multiple cross-site scripting (XSS) vulnerabilities in the mail_to helper in Ruby on Rails before 2.3.11, and 3.x before 3.0.4, when javascript encoding is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) name or (2) email value. Scope: local bookworm: resolved (fixed in 2.3.11-0.1) bullseye: resolved (fixed in 2.3.11-0.1) forky: r
debian
CVE-2023-28362P4MEDIUMCVSS 4.0fixed in rails 2:6.1.7.10+dfsg-1~deb12u1 (bookworm)2023
CVE-2023-28362 [MEDIUM] CVE-2023-28362: rails - The redirect_to method in Rails allows provided values to contain characters whi... The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header. Scope: local bookworm: resolved (fixed in 2:6.1.7.10+dfsg-1~deb12u1) bullseye: resolved (fixed in
debian
CVE-2025-55193P4LOWCVSS 2.7fixed in rails 2:6.1.7.10+dfsg-1~deb12u2 (bookworm)2025
CVE-2025-55193 [LOW] CVE-2025-55193: rails - Active Record connects classes to relational database tables. Prior to versions ... Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences. This issue has been patched in versions 7.1.5.2, 7.2.2.2, and 8.0.2.1. Scope: local bookworm: resolved (fixed
debian
CVE-2024-54133P4LOWCVSS 2.3fixed in rails 2:6.1.7.10+dfsg-1~deb12u1 (bookworm)2024
CVE-2024-54133 [LOW] CVE-2024-54133: rails - Action Pack is a framework for handling and responding to web requests. There is... Action Pack is a framework for handling and responding to web requests. There is a possible Cross Site Scripting (XSS) vulnerability in the `content_security_policy` helper starting in version 5.2.0 of Action Pack and prior to versions 7.0.8.7, 7.1.5.1, 7.2.2.1, and 8.0.0.1. Applications which set Content-Security-Policy (CSP) headers dynamically from untrusted user in
debian
Debian Rails vulnerabilities | cvebase