Jean Boussier
20 exploits
Active since Jul 2015
OpenSSH <9.6 - Open Redirect
CVSS 5.9
Rack 0.4-2.2.8.1 and 3.0.0-3.0.9.1 - Denial of Service via Content-Type Header Parsing
CVSS 5.3
Active Support <8.1.2.1/8.0.4.1/7.2.3.1 - DoS
CVSS 5.3
Active Support <8.1.2.1 - XSS
CVSS 6.1
Active Storage <8.1.2.1 - Auth Bypass
CVSS 5.3
ActiveSupport < 8.1.2.1, < 8.0.4.1, < 7.2.3.1 - Denial of Service via BigDecimal Scientific Notation Expansion
CVSS 7.5
Active Support <8.1.2.1/8.0.4.1/7.2.3.1 - DoS
CVSS 5.3
Active Support <8.1.2.1 - XSS
CVSS 6.1
Active Storage <8.1.2.1 - Auth Bypass
CVSS 5.3
ActiveSupport < 8.1.2.1, < 8.0.4.1, < 7.2.3.1 - Denial of Service via BigDecimal Scientific Notation Expansion
CVSS 7.5
Active Support <8.1.2.1/8.0.4.1/7.2.3.1 - DoS
CVSS 5.3
Active Support <8.1.2.1 - XSS
CVSS 6.1
Active Storage <8.1.2.1 - Auth Bypass
CVSS 5.3
ActiveSupport < 8.1.2.1, < 8.0.4.1, < 7.2.3.1 - Denial of Service via BigDecimal Scientific Notation Expansion
CVSS 7.5
Redcarpet < 3.3.2 - Stack-Based Buffer Overflow in HTML Renderer
Redcarpet < 3.5.1 - Cross-Site Scripting via Quote Processing
CVSS 6.8
Puma < 4.3.11 and 5.0.0-5.6.2 - Information Exposure via Response Body Handling
CVSS 8.0
Rack 0.4-2.2.8.1 and 3.0.0-3.0.9.1 - Denial of Service via Content-Type Header Parsing
CVSS 5.3
ruby-lang javascript_object_notation 2.10.0-2.10.1 - Out-of-bounds Read
CVSS 7.5
Pitchfork <0.11.0 - HTTP Response Header Injection
CVSS 4.3