thoughtbot records
6 published records for vendor thoughtbot.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-943 Improper Neutralization of Special Elements in Data Query Logic1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-0889No exploit | Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter clasthoughtbot · paperclip · CWE-918 | Critical9.8 | — | 3.1% | Nov 13, 2017 |
32Monitor | CVE-2020-5257No exploit | Sort order SQL injection in Administratethoughtbot · administrate · CWE-943 | High8.1 | — | 0.9% | Mar 13, 2020 |
28Monitor | CVE-2013-4457No exploit | The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, relathoughtbot · cocaine · CWE-78 | Medium6.8 | — | 2.0% | Nov 2, 2013 |
24Monitor | CVE-2021-23435No exploit | This affects the package clearance before 2.5.0.thoughtbot · clearance · CWE-601 | Medium6.1 | — | 0.7% | Sep 12, 2021 |
21Monitor | CVE-2016-3098No exploit | Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorizthoughtbot · administrate · CWE-352 | Medium5.4 | — | 0.4% | Aug 5, 2022 |
18Monitor | CVE-2015-2963No exploit | The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remotthoughtbot · paperclip · CWE-79 | Medium4.3 | — | 2.1% | Jul 10, 2015 |
- CVE-2017-088940Plan
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter clas
CriticalCVSS 9.8No exploitEPSS 3%thoughtbot · paperclipNov 13, 2017
- CVE-2020-525732Monitor
Sort order SQL injection in Administrate
HighCVSS 8.1No exploitEPSS 1%thoughtbot · administrateMar 13, 2020
- CVE-2013-445728Monitor
The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, rela
MediumCVSS 6.8No exploitEPSS 2%thoughtbot · cocaineNov 2, 2013
- CVE-2021-2343524Monitor
This affects the package clearance before 2.5.0.
MediumCVSS 6.1No exploitEPSS 1%thoughtbot · clearanceSep 12, 2021
- CVE-2016-309821Monitor
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autoriz
MediumCVSS 5.4No exploitEPSS 0%thoughtbot · administrateAug 5, 2022
- CVE-2015-296318Monitor
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remot
MediumCVSS 4.3No exploitEPSS 2%thoughtbot · paperclipJul 10, 2015