THE ADVISORY INDEX
Rails security, in the open.
Published advisories from the Rails maintainers, with a starting point for every investigation.
26 advisories
Possible arbitrary file read and remote code execution in Active Storage variant processing
activestorage
Possible XSS vulnerability in Action Pack debug exceptions
actionpack
Possible XSS vulnerability in Action View tag helpers
actionview
Possible XSS vulnerability in SafeBuffer#% in Active Support
activesupport
Possible ReDoS vulnerability in number_to_delimited in Active Support
activesupport
Possible DoS vulnerability in Active Support number helpers
activesupport
Insufficient filtering of metadata in Active Storage direct uploads
activestorage
Possible DoS vulnerability in Active Storage proxy mode via Range requests
activestorage
Possible DoS vulnerability in Active Storage proxy mode via multi-range requests
activestorage
Possible path traversal in Active Storage DiskService
activestorage
Possible glob injection in Active Storage DiskService
activestorage
Active Storage allowed transformation methods potentially unsafe
activestorage
ANSI escape injection in Active Record logging
activerecord
Possible Content Security Policy bypass in Action Dispatch
actionpack
Possible ReDoS vulnerability in query parameter filtering in Action Dispatch
actionpack
Possible ReDoS vulnerability in HTTP Token authentication in Action Controller
actionpack
Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
actiontext
Possible ReDoS vulnerability in block_format in Action Mailer
actionmailer
Missing security headers in Action Pack on non-HTML responses
actionpack
ActionText ContentAttachment can contain unsanitized HTML
actiontext
Possible ReDoS vulnerability in Accept header parsing in Action Dispatch
rails
Possible Sensitive Session Information Leak in Active Storage
rails
Possible XSS Vulnerability in Action Controller translation
rails
Possible exposure of information vulnerability in Action Pack
actionpack
Potential XSS vulnerability in Action View
actionview
Possible XSS vulnerability in ActionView
actionview