Skip to content
Noroxi

thoughtbot records

6 published records for vendor thoughtbot.

All records

6 records
  • Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter clas

    CriticalCVSS 9.8No exploitEPSS 3%

    thoughtbot · paperclipNov 13, 2017

  • CVE-2020-5257
    32Monitor

    Sort order SQL injection in Administrate

    HighCVSS 8.1No exploitEPSS 1%

    thoughtbot · administrateMar 13, 2020

  • CVE-2013-4457
    28Monitor

    The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, rela

    MediumCVSS 6.8No exploitEPSS 2%

    thoughtbot · cocaineNov 2, 2013

  • This affects the package clearance before 2.5.0.

    MediumCVSS 6.1No exploitEPSS 1%

    thoughtbot · clearanceSep 12, 2021

  • CVE-2016-3098
    21Monitor

    Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autoriz

    MediumCVSS 5.4No exploitEPSS 0%

    thoughtbot · administrateAug 5, 2022

  • CVE-2015-2963
    18Monitor

    The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remot

    MediumCVSS 4.3No exploitEPSS 2%

    thoughtbot · paperclipJul 10, 2015