Записи thoughtbot
6 опубликованных записей вендора thoughtbot.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-943 Improper Neutralization of Special Elements in Data Query Logic1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-0889Эксплойта нет | Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter clasthoughtbot · paperclip · CWE-918 | Критическая9,8 | — | 3,1 % | 13 нояб. 2017 г. |
32Наблюдать | CVE-2020-5257Эксплойта нет | Sort order SQL injection in Administratethoughtbot · administrate · CWE-943 | Высокая8,1 | — | 0,9 % | 13 мар. 2020 г. |
28Наблюдать | CVE-2013-4457Эксплойта нет | The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, relathoughtbot · cocaine · CWE-78 | Средняя6,8 | — | 2,0 % | 2 нояб. 2013 г. |
24Наблюдать | CVE-2021-23435Эксплойта нет | This affects the package clearance before 2.5.0.thoughtbot · clearance · CWE-601 | Средняя6,1 | — | 0,7 % | 12 сент. 2021 г. |
21Наблюдать | CVE-2016-3098Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorizthoughtbot · administrate · CWE-352 | Средняя5,4 | — | 0,4 % | 5 авг. 2022 г. |
18Наблюдать | CVE-2015-2963Эксплойта нет | The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remotthoughtbot · paperclip · CWE-79 | Средняя4,3 | — | 2,1 % | 10 июл. 2015 г. |
- CVE-2017-088940В плане
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter clas
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %thoughtbot · paperclip13 нояб. 2017 г.
- CVE-2020-525732Наблюдать
Sort order SQL injection in Administrate
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %thoughtbot · administrate13 мар. 2020 г.
- CVE-2013-445728Наблюдать
The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, rela
СредняяCVSS 6,8Эксплойта нетEPSS 2 %thoughtbot · cocaine2 нояб. 2013 г.
- CVE-2021-2343524Наблюдать
This affects the package clearance before 2.5.0.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %thoughtbot · clearance12 сент. 2021 г.
- CVE-2016-309821Наблюдать
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autoriz
СредняяCVSS 5,4Эксплойта нетEPSS 0 %thoughtbot · administrate5 авг. 2022 г.
- CVE-2015-296318Наблюдать
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remot
СредняяCVSS 4,3Эксплойта нетEPSS 2 %thoughtbot · paperclip10 июл. 2015 г.