activesupport
RubyGems14 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting activesupportpage 1 of 1
- CVE-2009-3009NONECVSS 0.0EG 0.0✓ Fixed in 2.3.42009-09-08
vulnerable: 2.3.2, 2.3.3
Cross-site scripting (XSS) vulnerability in Ruby on Rails 2.x before 2.2.3, and 2.3.x before 2.3.4, allows remote attackers to inject arbitrary web script or HTML by placing malformed Unicode strings into a form helper.
- CVE-2009-3086NONECVSS 0.0EG 0.0✓ Fixed in 2.3.42009-09-08
vulnerable: 2.3.2, 2.3.3
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via…
- CVE-2011-2197NONECVSS 0.0EG 0.0✓ Fixed in 3.0.82011-06-30
vulnerable: 3.0.0 ... 3.0.8.rc4 (17 versions)
The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct X…
- CVE-2011-2932NONECVSS 0.0EG 0.0✓ Fixed in 3.0.102011-08-29
vulnerable: 3.0.0 ... 3.0.9.rc5 (24 versions)
Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails 2.x before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary w…
- CVE-2012-1098NONECVSS 0.0EG 0.0✓ Fixed in 3.2.22012-03-13
vulnerable: 3.2.0, 3.2.1, 3.2.2.rc1
Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is mani…
- CVE-2012-3464NONECVSS 0.0EG 0.0✓ Fixed in 2.3.162012-08-10
vulnerable: 1.0.0 ... 2.3.9.pre (45 versions)
Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web s…
- CVE-2013-0333NONECVSS 0.0EG 9.0✓ Fixed in 3.0.202013-01-30
vulnerable: 3.0.0 ... 3.0.9.rc5 (36 versions)
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code…
- CVE-2013-1856NONECVSS 0.0EG 0.0✓ Fixed in 3.2.132013-03-19
vulnerable: 3.2.0 ... 3.2.9.rc3 (25 versions)
The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capab…
- CVE-2015-3226NONECVSS 0.0EG 0.0✓ Fixed in 4.2.22015-07-26
vulnerable: 4.2.0 ... 4.2.1.rc4 (6 versions)
Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mi…
- CVE-2015-3227NONECVSS 0.0EG 0.0✓ Fixed in 3.2.222015-07-26
vulnerable: 1.0.0 ... 3.2.9.rc3 (161 versions)
The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML docu…
- CVE-2020-8165CRITICALCVSS 9.8EG 9.8✓ Fixed in 6.0.3.12020-06-19
vulnerable: 6.0.0 ... 6.0.3.rc1 (10 versions)
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
- CVE-2023-22796HIGHCVSS 7.5EG 7.5✓ Fixed in 7.0.4.12023-02-09
vulnerable: 7.0.0 ... 7.0.4 (10 versions)
A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can cause the regular expression engine to enter a state of catastrophic backtracking. This ca…
- CVE-2023-28120MEDIUMCVSS 5.3EG 5.3✓ Fixed in 6.1.7.32025-01-09
vulnerable: 1.0.0 ... 6.1.7.2 (410 versions)
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
- CVE-2023-38037MEDIUMCVSS 5.5EG 5.5✓ Fixed in 7.0.7.12025-01-09
vulnerable: 7.0.0 ... 7.0.7 (17 versions)
ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user's current `umask` settings, meaning that it's possible for other users on the same syst…
Check whether activesupport is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for activesupport CVEs against the assets you own.
Start Free Scan →