Skip to main content

Vendor/product archive

rubyonrails / ruby_on_rails CVEs

Beta · best-effort

50 CVEs tagged to rubyonrails / ruby_on_rails2 Critical, 12 High, 35 Medium, 1 Low, 0 Unrated.

CVE-2017-17920

Published Dec 29, 2017

SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: Th…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17919

Published Dec 29, 2017

SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: T…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3226

Published Jul 26, 2015

Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to injec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0082

Published Feb 20, 2014

actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render me…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3221

Published Apr 22, 2013

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input va…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1856

Published Mar 19, 2013

The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0277

Published Feb 13, 2013

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes t…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0333

Published Jan 30, 2013

lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML par…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 50 CVEsPage 1 of 2