Vulnerabilities > Thoughtbot

DATE CVE VULNERABILITY TITLE RISK
2022-08-05 CVE-2016-3098 Cross-Site Request Forgery (CSRF) vulnerability in Thoughtbot Administrate
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code.
network
low complexity
thoughtbot CWE-352
5.4
2021-09-12 CVE-2021-23435 Open Redirect vulnerability in Thoughtbot Clearance
This affects the package clearance before 2.5.0.
network
low complexity
thoughtbot CWE-601
6.1
2020-03-13 CVE-2020-5257 SQL Injection vulnerability in Thoughtbot Administrate
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard, the direction parameter was not validated before being interpolated into the SQL query.
network
low complexity
thoughtbot CWE-89
8.1
2017-11-13 CVE-2017-0889 Server-Side Request Forgery (SSRF) vulnerability in Thoughtbot Paperclip
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class.
network
low complexity
thoughtbot CWE-918
critical
9.8