Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2018-16471

почти 8 лет назад

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-16471

почти 8 лет назад

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-16471

почти 8 лет назад

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-16471

почти 8 лет назад

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. ...

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1553-1

около 7 лет назад

Security update for rubygem-rack

EPSS: Низкий
github логотип

GHSA-5r2p-j47h-mhpg

почти 8 лет назад

Rack vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2019-03337

почти 8 лет назад

Уязвимость модуля Rack интерпретатора языка программирования Ruby, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0214-1

больше 6 лет назад

Security update for rubygem-rack

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0359-1

больше 6 лет назад

Security update for rubygem-rack

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-16471

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.

CVSS3: 6.1
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-16471

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.

CVSS3: 6.1
2%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-16471

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.

CVSS3: 6.1
2%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-16471

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. ...

CVSS3: 6.1
2%
Низкий
почти 8 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1553-1

Security update for rubygem-rack

2%
Низкий
около 7 лет назад
github логотип
GHSA-5r2p-j47h-mhpg

Rack vulnerable to Cross-site Scripting

CVSS3: 6.1
2%
Низкий
почти 8 лет назад
fstec логотип
BDU:2019-03337

Уязвимость модуля Rack интерпретатора языка программирования Ruby, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 6.1
2%
Низкий
почти 8 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0214-1

Security update for rubygem-rack

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:0359-1

Security update for rubygem-rack

больше 6 лет назад

Уязвимостей на страницу