Vulnerabilities > Rubyonrails > Rails > 6.1.4.2

DATE CVE VULNERABILITY TITLE RISK
2024-06-04 CVE-2024-28103 Unspecified vulnerability in Rubyonrails Rails
Action Pack is a framework for handling and responding to web requests.
network
low complexity
rubyonrails
critical
9.8
2024-02-27 CVE-2024-26144 Unspecified vulnerability in Rubyonrails Rails
Rails is a web-application framework.
network
low complexity
rubyonrails
5.3
2023-02-09 CVE-2023-22792 Unspecified vulnerability in Rubyonrails Rails
A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1.
network
low complexity
rubyonrails
7.5
2023-02-09 CVE-2023-22795 A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header.
network
low complexity
rubyonrails debian
7.5
2022-02-11 CVE-2022-23634 Improper Resource Shutdown or Release vulnerability in multiple products
Puma is a Ruby/Rack web server built for parallelism.
network
high complexity
puma rubyonrails debian fedoraproject CWE-404
5.9
2022-02-11 CVE-2022-23633 Improper Cross-boundary Removal of Sensitive Data vulnerability in multiple products
Action Pack is a framework for handling and responding to web requests.
network
high complexity
rubyonrails debian CWE-212
5.9
2022-01-10 CVE-2021-44528 Open Redirect vulnerability in Rubyonrails Rails 6.0.4.2/6.1.4.2/7.0.0
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
network
low complexity
rubyonrails CWE-601
6.1