Debian Rails vulnerabilities
139 known vulnerabilities affecting debian/rails.
Total CVEs
139
CISA KEV
2
actively exploited
Public exploits
13
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH30MEDIUM55LOW47
Vulnerabilities
Page 7 of 7
CVE-2011-0448LOWCVSS 7.52011
CVE-2011-0448 [HIGH] CVE-2011-0448: rails - Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit fun...
Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2011-0449LOWCVSS 7.52011
CVE-2011-0449 [HIGH] CVE-2011-0449: rails - actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3....
actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.
Scope: local
b
debian
CVE-2011-4319LOWCVSS 4.32011
CVE-2011-4319 [MEDIUM] CVE-2011-4319: rails - Cross-site scripting (XSS) vulnerability in the i18n translations helper method ...
Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with an "html" substring.
Scope: local
bookworm: resolve
debian
CVE-2011-2197LOWCVSS 4.32011
CVE-2011-2197 [MEDIUM] CVE-2011-2197: rails - The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2....
The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.
Scope: l
debian
CVE-2010-3933LOWCVSS 6.42010
CVE-2010-3933 [MEDIUM] CVE-2010-3933: rails - Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which ...
Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2010-3299LOWCVSS 6.52010
CVE-2010-3299 [MEDIUM] CVE-2010-3299: rails - The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding ora...
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2009-2422CRITICALCVSS 9.8fixed in rails 2.3.5-1 (bookworm)2009
CVE-2009-2422 [CRITICAL] CVE-2009-2422: rails - The example code for the digest authentication functionality (http_authenticatio...
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending a
debian
CVE-2009-3009LOWCVSS 4.3fixed in rails 2.2.3-1 (bookworm)2009
CVE-2009-3009 [MEDIUM] CVE-2009-3009: rails - Cross-site scripting (XSS) vulnerability in Ruby on Rails 2.x before 2.2.3, and ...
Cross-site scripting (XSS) vulnerability in Ruby on Rails 2.x before 2.2.3, and 2.3.x before 2.3.4, allows remote attackers to inject arbitrary web script or HTML by placing malformed Unicode strings into a form helper.
Scope: local
bookworm: resolved (fixed in 2.2.3-1)
bullseye: resolved (fixed in 2.2.3-1)
forky: resolved (fixed in 2.2.3-1)
sid: resolved (fixed in 2.
debian
CVE-2009-3086LOWCVSS 5.0fixed in rails 2.2.3-1 (bookworm)2009
CVE-2009-3086 [MEDIUM] CVE-2009-3086: rails - A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4...
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.
Scope: local
bookworm: resolved (fixed in 2.2.3-1)
bullseye: resolved (fixed in 2.2.3-1)
forky: resolved (fixed
debian
CVE-2009-4214LOWCVSS 4.3fixed in rails 2.2.3-2 (bookworm)2009
CVE-2009-4214 [MEDIUM] CVE-2009-4214: rails - Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on R...
Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.
Scope: local
bookworm: resolved (
debian
CVE-2008-7248MEDIUMCVSS 6.8PoCfixed in rails 2.2.3-1 (bookworm)2008
CVE-2008-7248 [MEDIUM] CVE-2008-7248: rails - Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for...
Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.
Scope: local
bookworm: resolved (fixed in 2.2.3-1)
bullseye: resolved (fix
debian
CVE-2008-4094MEDIUMCVSS 7.5fixed in rails 2.1.0-1 (bookworm)2008
CVE-2008-4094 [HIGH] CVE-2008-4094: rails - Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remot...
Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.
Scope: local
bookworm: resolved (fixed in 2.1.0-1)
bullseye: resolved (fixed in 2.1.0-1)
forky: resolved (fixed i
debian
CVE-2008-5189LOWCVSS 5.0fixed in rails 2.1.0-6 (bookworm)2008
CVE-2008-5189 [MEDIUM] CVE-2008-5189: rails - CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attacke...
CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.
Scope: local
bookworm: resolved (fixed in 2.1.0-6)
bullseye: resolved (fixed in 2.1.0-6)
forky: resolved (fixed in 2.1.0-6)
sid: resolved (fixed in 2.1.0-6)
trixie
debian
CVE-2007-5379MEDIUMCVSS 5.0fixed in rails 1.2.5-1 (bookworm)2007
CVE-2007-5379 [MEDIUM] CVE-2007-5379: rails - Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and Activ...
Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via the Hash.from_xml (Hash#from_xml) method, which uses XmlSimple (XML::Simple) unsafely, as demonstrated by reading passwords from the Pidgin (Gaim) .purple/accounts.xml file.
Scope: local
bookwo
debian
CVE-2007-5380MEDIUMCVSS 6.8fixed in rails 1.2.5-1 (bookworm)2007
CVE-2007-5380 [MEDIUM] CVE-2007-5380: rails - Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails,...
Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to "URL-based sessions."
Scope: local
bookworm: resolved (fixed in 1.2.5-1)
bullseye: resolved (fixed in 1.2.5-1)
forky: resolved (fixed in 1.2.5-1)
sid: resolved (fixed in 1.2.5-1)
trixie: resolved (fixed in 1
debian
CVE-2007-3227MEDIUMCVSS 4.3PoCfixed in rails 1.2.5-1 (bookworm)2007
CVE-2007-3227 [MEDIUM] CVE-2007-3227: rails - Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_j...
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.
Scope: local
bookworm: resolved (fixed in 1.2.5-1)
bullseye: resolved (fixed in 1.2.5-1)
forky: resolved (fixed in 1.2.5-1)
sid: resolved (fixed in 1.2.5-1)
trixie:
debian
CVE-2007-6077LOWCVSS 6.8fixed in rails 1.2.6-1 (bookworm)2007
CVE-2007-6077 [MEDIUM] CVE-2007-6077: rails - The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as u...
The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks. NOTE: this is due to an i
debian
CVE-2006-4112MEDIUMCVSS 7.5fixed in rails 1.1.6-1 (bookworm)2006
CVE-2006-4112 [HIGH] CVE-2006-4112: rails - Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Ra...
Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than CVE-2006-4111.
Scope: local
bookworm: resolved (fixe
debian
CVE-2006-4111MEDIUMCVSS 7.5fixed in rails 1.1.5-1 (bookworm)2006
CVE-2006-4111 [HIGH] CVE-2006-4111: rails - Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "se...
Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.
Scope: local
bookworm: resolved (fixed in 1.1.5-1)
bullseye: resolved (fixed in 1.1.5-1)
forky: resolved (fixed in 1.1.5-1)
sid: resolve
debian
← Previous7 / 7