Количество 9
Количество 9

BDU:2024-06653
Уязвимость программной платформы Ruby on Rails, связанная с неправильной нейтрализацией входных данных во время генерации веб-страницы, позволяющая нарушителю проводить межсайтовый скриптинг

CVE-2024-26143
Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1.

CVE-2024-26143
Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1.

CVE-2024-26143
Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1.
CVE-2024-26143
Rails is a web-application framework. There is a possible XSS vulnerab ...
GHSA-9822-6m93-xqf4
Rails has possible XSS Vulnerability in Action Controller

ROS-20240827-20
Множественные уязвимости rubygem-actionpack

ROS-20240827-19
Множественные уязвимости rubygem-activestorage

ROS-20240827-06
Множественные уязвимости ruby
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | BDU:2024-06653 Уязвимость программной платформы Ruby on Rails, связанная с неправильной нейтрализацией входных данных во время генерации веб-страницы, позволяющая нарушителю проводить межсайтовый скриптинг | CVSS3: 6.1 | 1% Низкий | больше 1 года назад |
![]() | CVE-2024-26143 Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1. | CVSS3: 6.1 | 1% Низкий | больше 1 года назад |
![]() | CVE-2024-26143 Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1. | CVSS3: 4.1 | 1% Низкий | больше 1 года назад |
![]() | CVE-2024-26143 Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1. | CVSS3: 6.1 | 1% Низкий | больше 1 года назад |
CVE-2024-26143 Rails is a web-application framework. There is a possible XSS vulnerab ... | CVSS3: 6.1 | 1% Низкий | больше 1 года назад | |
GHSA-9822-6m93-xqf4 Rails has possible XSS Vulnerability in Action Controller | CVSS3: 6.1 | 1% Низкий | больше 1 года назад | |
![]() | ROS-20240827-20 Множественные уязвимости rubygem-actionpack | CVSS3: 6.1 | 10 месяцев назад | |
![]() | ROS-20240827-19 Множественные уязвимости rubygem-activestorage | CVSS3: 6.1 | 10 месяцев назад | |
![]() | ROS-20240827-06 Множественные уязвимости ruby | CVSS3: 6.1 | 10 месяцев назад |
Уязвимостей на страницу