Ruby on Rails: Security

Showing 1-20 of 85 topics
[CVE-2015-3227] Possible Denial of Service attack in Active Support Aaron Patterson 6/16/15
[CVE-2015-3224] IP whitelist bypass in Web Console Aaron Patterson 6/16/15
[CVE-2015-3226] XSS Vulnerability in ActiveSupport::JSON.encode Aaron Patterson 6/16/15
[CVE-2015-1840] CSRF Vulnerability in jquery-ujs and jquery-rails Aaron Patterson 6/16/15
[CVE-2015-3225] Potential Denial of Service Vulnerability in Rack Aaron Patterson 6/16/15
[AMENDED] [CVE-2014-7829] Arbitrary file existence disclosure in Action Pack Aaron Patterson 11/20/14
[CVE-2014-7829] Arbitrary file existence disclosure in Action Pack Aaron Patterson 11/17/14
[AMENDED] [CVE-2014-7819] Arbitrary file existence disclosure in Sprockets Aaron Patterson 10/30/14
Arbitrary file existence disclosure in Sprockets (CVE-2014-7819) Aaron Patterson 10/30/14
Arbitrary file existence disclosure in Action Pack (CVE-2014-7818) Aaron Patterson 10/30/14
[Ruby on Rails] [CVE-2014-3514] Strong Parameter bypass with create_with Rafael Mendonça França 8/18/14
Amended Patches for CVE-2014-3483 for Rails 4.x Rafael Mendonça França 7/2/14
[CVE-2014-3482] [CVE-2014-3483] Two Active Record SQL Injection Vulnerabilities Affecting PostgreSQL Rafael Mendonça França 7/2/14
[AMENDED] [CVE-2014-0130] Directory Traversal Vulnerability With Certain Route Configurations Rafael Mendonça França 5/6/14
Unsafe Query Risk in Active Record Rafael Mendonça França 5/6/14
[CVE-2014-0130] Directory Traversal Vulnerability With Certain Route Configurations Rafael Mendonça França 5/6/14
Denial of Service Vulnerability in Action View when using render :text (CVE-2014-0082) Aaron Patterson 2/18/14
Data Injection Vulnerability in Active Record (CVE-2014-0080) Aaron Patterson 2/18/14
XSS Vulnerability in number_to_currency, number_to_percentage and number_to_human (CVE-2014-0081) Aaron Patterson 2/18/14
[CVE-2013-6416] XSS Vulnerability in simple_format helper Aaron Patterson 12/3/13
More topics »