Search CVE reports


Toggle filters

21 – 30 of 33 results


CVE-2018-16470

Medium priority
Ignored

There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-rack Not affected Not affected
Show less packages

CVE-2018-16471

Medium priority

Some fixes available 3 of 4

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http'...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-rack Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-1000119

Medium priority

Some fixes available 2 of 3

Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via...

1 affected package

ruby-rack-protection

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-rack-protection Fixed Fixed
Show less packages

CVE-2017-11173

Medium priority

Some fixes available 2 of 3

Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com domain name and not the malicious...

1 affected package

ruby-rack-cors

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-rack-cors Not affected Fixed
Show less packages

CVE-2015-3225

Low priority

Some fixes available 2 of 10

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.

3 affected packages

librack-ruby, ruby-rack, ruby-rack1.4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
librack-ruby Not in release Not in release Not in release Not in release
ruby-rack Not affected Not affected Not affected Not affected
ruby-rack1.4 Not in release Not in release Not in release Not in release
Show less packages

CVE-2014-2538

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in lib/rack/ssl.rb in the rack-ssl gem before 1.4.0 for Ruby allows remote attackers to inject arbitrary web script or HTML via a URI, which might not be properly handled by third-party...

1 affected package

ruby-rack-ssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-rack-ssl Not affected Not affected
Show less packages

CVE-2013-0184

Low priority

Some fixes available 8 of 11

Unspecified vulnerability in Rack::Auth::AbstractRequest in Rack 1.1.x before 1.1.5, 1.2.x before 1.2.7, 1.3.x before 1.3.9, and 1.4.x before 1.4.4 allows remote attackers to cause a denial of service via unknown vectors related...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-rack Fixed
Show less packages

CVE-2013-0183

Low priority

Some fixes available 8 of 11

multipart/parser.rb in Rack 1.3.x before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a long string in a Multipart HTTP packet.

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-rack Fixed
Show less packages

CVE-2012-6109

Low priority

Some fixes available 8 of 11

lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3.7, and 1.4.x before 1.4.2 uses an incorrect regular expression, which allows remote attackers to cause a denial of service (infinite loop) via a...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-rack Fixed
Show less packages

CVE-2013-0263

Medium priority

Some fixes available 8 of 11

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-rack Fixed
Show less packages