📦 Rails

by Rubyonrails

🔍 What is Rails?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-22792

HIGH CVSS 7.5 Feb 9, 2023

This CVE describes a ReDoS (Regular Expression Denial of Service) vulnerability in Ruby on Rails Action Dispatch. Attackers can cause excessive CPU and memory usage by sending specially crafted cookie...

CVE-2023-22795

HIGH CVSS 7.5 Feb 9, 2023

This CVE describes a ReDoS (Regular Expression Denial of Service) vulnerability in Ruby on Rails Action Dispatch. Attackers can send specially crafted HTTP If-None-Match headers to cause catastrophic ...

CVE-2022-23633

HIGH CVSS 7.4 Feb 11, 2022

CVE-2022-23633 is a data leakage vulnerability in Ruby on Rails Action Pack where response bodies may not be properly closed, causing thread local state to persist between requests. This allows sensit...

CVE-2021-22904

HIGH CVSS 7.5 Jun 11, 2021

This vulnerability in Ruby on Rails' Actionpack gem allows attackers to cause denial of service through token authentication. A too-permissive regular expression in the HTTP token authentication logic...

CVE-2021-22885

HIGH CVSS 7.5 May 27, 2021

This vulnerability in Ruby on Rails Action Pack allows attackers to perform information disclosure or unintended method execution when using redirect_to or polymorphic_url helpers with untrusted user ...

CVE-2024-28103

MEDIUM CVSS 5.4 Jun 4, 2024

This vulnerability in Ruby on Rails Action Pack causes the Permissions-Policy HTTP header to be omitted from non-HTML responses, potentially allowing cross-origin resource access that should be restri...