Product:

Ruby_on_rails

(Rubyonrails)
Repositories https://github.com/rails/rails
#Vulnerabilities 50
Date Id Summary Products Score Patch Annotated
2017-12-29 CVE-2017-17919 SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input Ruby_on_rails 8.1
2017-12-29 CVE-2017-17920 SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input Ruby_on_rails 8.1
2009-07-10 CVE-2009-2422 The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password. Mac_os_x, Mac_os_x_server, Ruby_on_rails 9.8