İçeriğe atla
Noroxi

thoughtbot kayıtları

thoughtbot üreticisine ait 6 yayımlanmış kayıt.

Tüm kayıtlar

6 kayıt
  • CVE-2017-0889
    40Planlayın

    Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter clas

    KritikCVSS 9,8İstismar yokEPSS %3

    thoughtbot · paperclip13 Kas 2017

  • CVE-2020-5257
    32İzleyin

    Sort order SQL injection in Administrate

    YüksekCVSS 8,1İstismar yokEPSS %1

    thoughtbot · administrate13 Mar 2020

  • CVE-2013-4457
    28İzleyin

    The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, rela

    OrtaCVSS 6,8İstismar yokEPSS %2

    thoughtbot · cocaine2 Kas 2013

  • CVE-2021-23435
    24İzleyin

    This affects the package clearance before 2.5.0.

    OrtaCVSS 6,1İstismar yokEPSS %1

    thoughtbot · clearance12 Eyl 2021

  • CVE-2016-3098
    21İzleyin

    Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autoriz

    OrtaCVSS 5,4İstismar yokEPSS %0

    thoughtbot · administrate5 Ağu 2022

  • CVE-2015-2963
    18İzleyin

    The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remot

    OrtaCVSS 4,3İstismar yokEPSS %2

    thoughtbot · paperclip10 Tem 2015