rails Vulnerabilities and Affected Products
Vulnerabilities associated with https://github.com/rails/rails.
Products
Clear product- rails14 vulnerabilities
- rails-html-sanitizer11 vulnerabilities
- activestorage6 vulnerabilities
- activesupport5 vulnerabilities
- actionview3 vulnerabilities
- https://github.com/rails/rails3 vulnerabilities
- Ruby on Rails3 vulnerabilities
- Action Pack1 vulnerability
- actionpack1 vulnerability
- Kredis JSON1 vulnerability
- Rack1 vulnerability
- rails-ujs1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-5420CRITICAL | Use of Insufficiently Random Values in Railties Allows Remote Code ExecutionA remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit. | CVSS9.8v3.1 | EPSS92.1% | PoCs15 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-5419HIGH | Denial of Service Vulnerability in Action ViewThere is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive. | CVSS7.5v3.1 | EPSS8.67% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-5418HIGH | Path Traversal in Action ViewThere is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed. | CVSS7.5v3.1 | EPSS98.5% | PoCs14 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |