Showing 3 vulnerabilities on this page for https://github.com/rails/rails

Signals CISA KEV Ransomware Nuclei
rails vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Use of Insufficiently Random Values in Railties Allows Remote Code Execution

A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.

CWE-330CWE-77Mar 27, 2019
CVSS9.8v3.1EPSS92.1%PoCs15SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Denial of Service Vulnerability in Action View

There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.

CWE-400CWE-770Mar 27, 2019
CVSS7.5v3.1EPSS8.67%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Path Traversal in Action View

There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.

CWE-22Mar 27, 20191 related artifact
CVSS7.5v3.1EPSS98.5%PoCs14SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX