Search CVE reports


Toggle filters

21 – 30 of 37 results


CVE-2020-8184

Medium priority

Some fixes available 5 of 8

A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Not affected Fixed Fixed
Show less packages

CVE-2020-8161

Low priority

Some fixes available 4 of 5

A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Not affected Fixed Fixed
Show less packages

CVE-2019-18978

Medium priority

Some fixes available 1 of 4

An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in...

1 affected package

ruby-rack-cors

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack-cors Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2019-16782

Medium priority

Some fixes available 4 of 6

There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-16471

Medium priority

Some fixes available 3 of 4

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http'...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Not affected Not affected Fixed
Show less packages

CVE-2018-16470

Medium priority
Ignored

There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate...

1 affected package

ruby-rack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Not affected
Show less packages

CVE-2018-1000119

Medium priority

Some fixes available 2 of 3

Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via...

1 affected package

ruby-rack-protection

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack-protection Fixed
Show less packages

CVE-2017-11173

Medium priority

Some fixes available 2 of 3

Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com domain name and not the malicious...

1 affected package

ruby-rack-cors

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack-cors Not affected
Show less packages

CVE-2015-3225

Low priority

Some fixes available 2 of 10

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.

3 affected packages

ruby-rack, ruby-rack1.4, librack-ruby

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack Not affected Not affected Not affected
ruby-rack1.4 Not in release Not in release Not in release
librack-ruby Not in release Not in release Not in release
Show less packages

CVE-2014-2538

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in lib/rack/ssl.rb in the rack-ssl gem before 1.4.0 for Ruby allows remote attackers to inject arbitrary web script or HTML via a URI, which might not be properly handled by third-party...

1 affected package

ruby-rack-ssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rack-ssl Not affected
Show less packages