Groups
Sign in
Groups
Ruby on Rails: Security
Conversations
About
Send feedback
Help
Ruby on Rails: Security
Contact owners and managers
1–30 of 140
Mark all as read
Report group
0 selected
Aaron Patterson
Feb 22
Mailing List Retirement
Hi folks, This is an update just to let you all know we're retiring this mailing list. Actually
unread,
Mailing List Retirement
Hi folks, This is an update just to let you all know we're retiring this mailing list. Actually
Feb 22
Aaron Patterson
7/12/22
[CVE-2022-32224] Possible RCE escalation bug with Serialized Columns in Active Record
There is a possible escalation to RCE when using YAML serialized columns in Active Record. This
unread,
[CVE-2022-32224] Possible RCE escalation bug with Serialized Columns in Active Record
There is a possible escalation to RCE when using YAML serialized columns in Active Record. This
7/12/22
Mike Dalessio
6/9/22
[CVE-2022-32209] Possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer
There is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer. This
unread,
[CVE-2022-32209] Possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer
There is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer. This
6/9/22
Aaron Patterson
5/27/22
[CVE-2022-30123] Possible shell escape sequence injection vulnerability in Rack
There is a possible shell escape sequence injection vulnerability in the Lint and CommonLogger
unread,
[CVE-2022-30123] Possible shell escape sequence injection vulnerability in Rack
There is a possible shell escape sequence injection vulnerability in the Lint and CommonLogger
5/27/22
Aaron Patterson
5/27/22
[CVE-2022-30122] Denial of Service Vulnerability in Rack Multipart Parsing
There is a possible denial of service vulnerability in the multipart parsing component of Rack. This
unread,
[CVE-2022-30122] Denial of Service Vulnerability in Rack Multipart Parsing
There is a possible denial of service vulnerability in the multipart parsing component of Rack. This
5/27/22
Aaron Patterson
4/26/22
[CVE-2022-27777] Possible XSS Vulnerability in Action View tag helpers
There is a possible XSS vulnerability in Action View tag helpers. Passing untrusted input as hash
unread,
[CVE-2022-27777] Possible XSS Vulnerability in Action View tag helpers
There is a possible XSS vulnerability in Action View tag helpers. Passing untrusted input as hash
4/26/22
Aaron Patterson
4/26/22
[CVE-2022-22577] Possible XSS Vulnerability in Action Pack
There is a possible XSS vulnerability in Rails / Action Pack. This vulnerability has been assigned
unread,
[CVE-2022-22577] Possible XSS Vulnerability in Action Pack
There is a possible XSS vulnerability in Rails / Action Pack. This vulnerability has been assigned
4/26/22
Aaron Patterson
3/8/22
[CVE-2022-21831] Possible code injection vulnerability in Rails / Active Storage
There is a possible code injection vulnerability in the Active Storage module of Rails. This
unread,
[CVE-2022-21831] Possible code injection vulnerability in Rails / Active Storage
There is a possible code injection vulnerability in the Active Storage module of Rails. This
3/8/22
Aaron Patterson
2/11/22
[CVE-2022-23633] Possible exposure of information vulnerability in Action Pack
## Impact Under certain circumstances response bodies will not be closed, for example a bug in a
unread,
[CVE-2022-23633] Possible exposure of information vulnerability in Action Pack
## Impact Under certain circumstances response bodies will not be closed, for example a bug in a
2/11/22
Aaron Patterson
12/14/21
[CVE-2021-44528] Possible Open Redirect in Host Authorization Middleware
There is a possible open redirect vulnerability in the Host Authorization middleware in Action Pack.
unread,
[CVE-2021-44528] Possible Open Redirect in Host Authorization Middleware
There is a possible open redirect vulnerability in the Host Authorization middleware in Action Pack.
12/14/21
Aaron Patterson
8/19/21
[CVE-2021-22942] Possible Open Redirect in Host Authorization Middleware
# Possible Open Redirect in Host Authorization Middleware There is a possible open redirect
unread,
[CVE-2021-22942] Possible Open Redirect in Host Authorization Middleware
# Possible Open Redirect in Host Authorization Middleware There is a possible open redirect
8/19/21
Aaron Patterson
5/5/21
[CVE-2021-22904] Possible DoS Vulnerability in Action Controller Token Authentication
There is a possible DoS vulnerability in the Token Authentication logic in Action Controller. This
unread,
[CVE-2021-22904] Possible DoS Vulnerability in Action Controller Token Authentication
There is a possible DoS vulnerability in the Token Authentication logic in Action Controller. This
5/5/21
Aaron Patterson
5/5/21
[CVE-2021-22885] Possible Information Disclosure / Unintended Method Execution in Action Pack
There is a possible information disclosure / unintended method execution vulnerability in Action Pack
unread,
[CVE-2021-22885] Possible Information Disclosure / Unintended Method Execution in Action Pack
There is a possible information disclosure / unintended method execution vulnerability in Action Pack
5/5/21
Aaron Patterson
5/5/21
[CVE-2021-22903] Possible Open Redirect Vulnerability in Action Pack
There is a possible Open Redirect Vulnerability in Action Pack. This vulnerability has been assigned
unread,
[CVE-2021-22903] Possible Open Redirect Vulnerability in Action Pack
There is a possible Open Redirect Vulnerability in Action Pack. This vulnerability has been assigned
5/5/21
Aaron Patterson
5/5/21
[CVE-2021-22902] Possible Denial of Service vulnerability in Action Dispatch
There is a possible Denial of Service vulnerability in the Mime type parser of Action Dispatch. This
unread,
[CVE-2021-22902] Possible Denial of Service vulnerability in Action Dispatch
There is a possible Denial of Service vulnerability in the Mime type parser of Action Dispatch. This
5/5/21
Rafael França
2/10/21
[CVE-2021-22881] Possible Open Redirect in Host Authorization Middleware
There is a possible open redirect vulnerability in the Host Authorization middleware in Action Pack.
unread,
[CVE-2021-22881] Possible Open Redirect in Host Authorization Middleware
There is a possible open redirect vulnerability in the Host Authorization middleware in Action Pack.
2/10/21
Rafael França
2/10/21
[CVE-2021-22880] Possible DoS Vulnerability in Active Record PostgreSQL adapter
There is a possible DoS vulnerability in the PostgreSQL adapter in Active Record. This vulnerability
unread,
[CVE-2021-22880] Possible DoS Vulnerability in Active Record PostgreSQL adapter
There is a possible DoS vulnerability in the PostgreSQL adapter in Active Record. This vulnerability
2/10/21
Aaron Patterson
10/7/20
[CVE-2020-8264] Possible XSS Vulnerability in Action Pack in Development Mode
There is a possible XSS vulnerability in Action Pack while the application server is in development
unread,
[CVE-2020-8264] Possible XSS Vulnerability in Action Pack in Development Mode
There is a possible XSS vulnerability in Action Pack while the application server is in development
10/7/20
George Claghorn
9/9/20
[CVE-2020-15169] Potential XSS vulnerability in Action View
There is a potential Cross-Site Scripting (XSS) vulnerability in Action View's translation
unread,
[CVE-2020-15169] Potential XSS vulnerability in Action View
There is a potential Cross-Site Scripting (XSS) vulnerability in Action View's translation
9/9/20
Aaron Patterson
2
6/17/20
[CVE-2020-8185] Untrusted users able to run pending migrations in production
Sorry, I forgot to attach the patch! It's here
unread,
[CVE-2020-8185] Untrusted users able to run pending migrations in production
Sorry, I forgot to attach the patch! It's here
6/17/20
Aaron Patterson
6/15/20
[CVE-2020-8184] Percent-encoded cookies can be used to overwrite existing prefixed cookie names
Percent-encoded cookies can be used to overwrite existing prefixed cookie names It is possible to
unread,
[CVE-2020-8184] Percent-encoded cookies can be used to overwrite existing prefixed cookie names
Percent-encoded cookies can be used to overwrite existing prefixed cookie names It is possible to
6/15/20
Aaron Patterson
5/18/20
[CVE-2020-8167] CSRF Vulnerability in rails-ujs
CSRF Vulnerability in rails-ujs There is an vulnerability in rails-ujs that allows attackers to send
unread,
[CVE-2020-8167] CSRF Vulnerability in rails-ujs
CSRF Vulnerability in rails-ujs There is an vulnerability in rails-ujs that allows attackers to send
5/18/20
Aaron Patterson
5/18/20
[CVE-2020-8166] Ability to forge per-form CSRF tokens given a global CSRF token
Ability to forge per-form CSRF tokens given a global CSRF token It is possible to possible to, given
unread,
[CVE-2020-8166] Ability to forge per-form CSRF tokens given a global CSRF token
Ability to forge per-form CSRF tokens given a global CSRF token It is possible to possible to, given
5/18/20
Aaron Patterson
5/18/20
[CVE-2020-8165] Potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
Potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
unread,
[CVE-2020-8165] Potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
Potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
5/18/20
Aaron Patterson
5/18/20
[CVE-2020-8164] Possible Strong Parameters Bypass in ActionPack
# Possible Strong Parameters Bypass in ActionPack There is a strong parameters bypass vector in
unread,
[CVE-2020-8164] Possible Strong Parameters Bypass in ActionPack
# Possible Strong Parameters Bypass in ActionPack There is a strong parameters bypass vector in
5/18/20
Aaron Patterson
5/18/20
[CVE-2020-8162] Circumvention of file size limits in ActiveStorage
Circumvention of file size limits in ActiveStorage There is a vulnerability in ActiveStorage's S3
unread,
[CVE-2020-8162] Circumvention of file size limits in ActiveStorage
Circumvention of file size limits in ActiveStorage There is a vulnerability in ActiveStorage's S3
5/18/20
Aaron Patterson
2
5/15/20
[CVE-2020-8163] Potential remote code execution of user-provided local names in Rails < 5.0.1
Hi, There was an error in the patch so I've attached a new patch. Please apply this patch or
unread,
[CVE-2020-8163] Potential remote code execution of user-provided local names in Rails < 5.0.1
Hi, There was an error in the patch so I've attached a new patch. Please apply this patch or
5/15/20
Aaron Patterson
5/12/20
[CVE-2020-8161] Directory traversal in Rack::Directory
Directory traversal in Rack::Directory There was a possible directory traversal vulnerability in the
unread,
[CVE-2020-8161] Directory traversal in Rack::Directory
Directory traversal in Rack::Directory There was a possible directory traversal vulnerability in the
5/12/20
Aaron Patterson
5/6/20
[CVE-2020-8159] Arbitrary file write/potential remote code execution in actionpack_page-caching
Arbitrary file write/potential remote code execution in actionpack_page-caching There is a
unread,
[CVE-2020-8159] Arbitrary file write/potential remote code execution in actionpack_page-caching
Arbitrary file write/potential remote code execution in actionpack_page-caching There is a
5/6/20
Aaron Patterson
5/5/20
[CVE-2020-8151] Possible information disclosure issue in Active Resource
There is a possible information disclosure issue in Active Resource. This vulnerability has been
unread,
[CVE-2020-8151] Possible information disclosure issue in Active Resource
There is a possible information disclosure issue in Active Resource. This vulnerability has been
5/5/20