Записи activerecord project
3 опубликованных записей вендора activerecord project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption1
- CWE-502 Deserialization of Untrusted Data1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
3 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2022-32224Proof of concept | A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2activerecord project · activerecord · CWE-502 | Критическая9,8 | — | 2,5 % | 5 дек. 2022 г. |
36Наблюдать | CVE-2023-22794Эксплойта нет | A vulnerability in ActiveRecord <6.0.6.1, v6.1.7.1 and v7.0.4.1 related to the sanitization of comments.activerecord project · activerecord · CWE-89 | Высокая8,8 | — | 2,2 % | 9 февр. 2023 г. |
30Наблюдать | CVE-2022-44566Эксплойта нет | A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1.activerecord project · activerecord · CWE-400 | Высокая7,5 | — | 1,3 % | 9 февр. 2023 г. |
- CVE-2022-3222440В плане
A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2
КритическаяCVSS 9,8Proof of conceptEPSS 2 %activerecord project · activerecord5 дек. 2022 г.
- CVE-2023-2279436Наблюдать
A vulnerability in ActiveRecord <6.0.6.1, v6.1.7.1 and v7.0.4.1 related to the sanitization of comments.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %activerecord project · activerecord9 февр. 2023 г.
- CVE-2022-4456630Наблюдать
A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %activerecord project · activerecord9 февр. 2023 г.