Количество 10
Количество 10
CVE-2024-26143
Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1.
CVE-2024-26143
Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1.
CVE-2024-26143
Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1.
CVE-2024-26143
Rails is a web-application framework. There is a possible XSS vulnerab ...
GHSA-9822-6m93-xqf4
Rails has possible XSS Vulnerability in Action Controller
BDU:2024-06653
Уязвимость программной платформы Ruby on Rails, связанная с неправильной нейтрализацией входных данных во время генерации веб-страницы, позволяющая нарушителю проводить межсайтовый скриптинг
ROS-20240827-20
Множественные уязвимости rubygem-actionpack
ROS-20240827-19
Множественные уязвимости rubygem-activestorage
ROS-20240827-06
Множественные уязвимости ruby
ALT-PU-2025-3714
ALT-PU-2025-3714: package `gem-rails` update to version 7.1.5.1-alt1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-26143 Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1. | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
CVE-2024-26143 Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1. | CVSS3: 4.1 | 1% Низкий | больше 2 лет назад | |
CVE-2024-26143 Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1. | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
CVE-2024-26143 Rails is a web-application framework. There is a possible XSS vulnerab ... | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
GHSA-9822-6m93-xqf4 Rails has possible XSS Vulnerability in Action Controller | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
BDU:2024-06653 Уязвимость программной платформы Ruby on Rails, связанная с неправильной нейтрализацией входных данных во время генерации веб-страницы, позволяющая нарушителю проводить межсайтовый скриптинг | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
ROS-20240827-20 Множественные уязвимости rubygem-actionpack | CVSS3: 6.1 | около 2 лет назад | ||
ROS-20240827-19 Множественные уязвимости rubygem-activestorage | CVSS3: 6.1 | около 2 лет назад | ||
ROS-20240827-06 Множественные уязвимости ruby | CVSS3: 6.1 | около 2 лет назад | ||
ALT-PU-2025-3714 ALT-PU-2025-3714: package `gem-rails` update to version 7.1.5.1-alt1 | CVSS3: 9.8 | больше 1 года назад |
Уязвимостей на страницу