bturtu405 / TestDev

0 stars 0 forks source link

[Snyk] Security upgrade rails from 3.0.7 to 6.1.7.3 #148

Open snyk-bot opened 1 year ago

snyk-bot commented 1 year ago

Snyk has created this PR to fix one or more vulnerable packages in the `rubygems` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Denial of Service (DoS)
SNYK-RUBY-ACTIONMAILER-20112
No No Known Exploit
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Information Exposure
SNYK-RUBY-ACTIONPACK-1290051
Yes Proof of Concept
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-ACTIONPACK-1290052
Yes No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONPACK-20020
No No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONPACK-20024
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Denial of Service (DoS)
SNYK-RUBY-ACTIONPACK-20035
No No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONPACK-20037
No No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONPACK-20038
No No Known Exploit
high severity 794/1000
Why? Mature exploit, Has a fix available, CVSS 7.3
Arbitrary Code Execution
SNYK-RUBY-ACTIONPACK-20047
No Mature
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONPACK-20087
No No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONPACK-20090
No No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONPACK-20120
No No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONPACK-20121
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Denial of Service (DoS)
SNYK-RUBY-ACTIONPACK-20122
No No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONPACK-20123
No No Known Exploit
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
Unsafe Query Generation Risk
SNYK-RUBY-ACTIONPACK-20125
No No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONPACK-20147
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Denial of Service (DoS)
SNYK-RUBY-ACTIONPACK-20148
No No Known Exploit
medium severity 644/1000
Why? Mature exploit, Has a fix available, CVSS 4.3
Directory Traversal
SNYK-RUBY-ACTIONPACK-20158
No Mature
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Arbitrary File Existence Exposure
SNYK-RUBY-ACTIONPACK-20198
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Arbitrary File Existence Exposure
SNYK-RUBY-ACTIONPACK-20200
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-ACTIONPACK-20256
No No Known Exploit
low severity 399/1000
Why? Has a fix available, CVSS 3.7
Timing Attack
SNYK-RUBY-ACTIONPACK-20258
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Arbitrary View Rendering
SNYK-RUBY-ACTIONPACK-20279
No No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONPACK-20281
No No Known Exploit
high severity 584/1000
Why? Has a fix available, CVSS 7.4
Information Exposure
SNYK-RUBY-ACTIONPACK-2400638
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ACTIONPACK-3237231
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ACTIONPACK-3237232
Yes No Known Exploit
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Cross-site Request Forgery (CSRF)
SNYK-RUBY-ACTIONPACK-569599
Yes Proof of Concept
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Information Exposure
SNYK-RUBY-ACTIONPACK-569600
Yes Proof of Concept
high severity 579/1000
Why? Has a fix available, CVSS 7.3
Data Injection
SNYK-RUBY-ACTIVERECORD-1314522
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
SQL Injection
SNYK-RUBY-ACTIVERECORD-20029
No No Known Exploit
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
Unsafe Query Generation
SNYK-RUBY-ACTIVERECORD-20030
No No Known Exploit
high severity 579/1000
Why? Has a fix available, CVSS 7.3
SQL Injection
SNYK-RUBY-ACTIVERECORD-20044
No No Known Exploit
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
JSON Parameter Parsing Query Bypass
SNYK-RUBY-ACTIVERECORD-20046
No No Known Exploit
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Remote Code Execution
SNYK-RUBY-ACTIVERECORD-20061
No No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Access Restriction Bypass
SNYK-RUBY-ACTIVERECORD-20062
No No Known Exploit
high severity 579/1000
Why? Has a fix available, CVSS 7.3
SQL Injection
SNYK-RUBY-ACTIVERECORD-20185
No No Known Exploit
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Remote Code Execution (RCE)
SNYK-RUBY-ACTIVERECORD-2960802
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-ACTIVERECORD-3237239
Yes No Known Exploit
high severity 579/1000
Why? Has a fix available, CVSS 7.3
SQL Injection
SNYK-RUBY-ACTIVERECORD-536100
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Information Exposure
SNYK-RUBY-ACTIVERESOURCE-568275
Yes No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIVESUPPORT-20025
No No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIVESUPPORT-20036
No No Known Exploit
high severity 794/1000
Why? Mature exploit, Has a fix available, CVSS 7.3
Arbitrary Code Injection
SNYK-RUBY-ACTIVESUPPORT-20054
No Mature
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Denial of Service (DoS)
SNYK-RUBY-ACTIVESUPPORT-20229
No No Known Exploit
medium severity 484/1000
Why? Has a fix available, CVSS 5.4
Denial of Service (DoS)
SNYK-RUBY-ACTIVESUPPORT-20294
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ACTIVESUPPORT-3237242
Yes No Known Exploit
medium severity 591/1000
Why? Recently disclosed, Has a fix available, CVSS 6.1
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIVESUPPORT-3360028
Yes No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIVESUPPORT-536101
No No Known Exploit
high severity 834/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-RUBY-ACTIVESUPPORT-569598
Yes Mature
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-I18N-20124
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-I18N-72582
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Directory Traversal
SNYK-RUBY-MAIL-20026
No No Known Exploit
high severity 579/1000
Why? Has a fix available, CVSS 7.3
Remote Shell Command Execution
SNYK-RUBY-MAIL-20027
No No Known Exploit
medium severity 519/1000
Why? Has a fix available, CVSS 6.1
SMTP Injection
SNYK-RUBY-MAIL-20244
No No Known Exploit
medium severity 616/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.9
Web Cache Poisoning
SNYK-RUBY-RACK-1061917
No Proof of Concept
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Denial of Service (DoS)
SNYK-RUBY-RACK-20021
No No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-RACK-20028
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Denial of Service (DoS)
SNYK-RUBY-RACK-20045
No No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Denial of Service (DoS)
SNYK-RUBY-RACK-20052
No No Known Exploit
medium severity 536/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 4.3
Arbitrary File Disclosure
SNYK-RUBY-RACK-20058
No Proof of Concept
medium severity 494/1000
Why? Has a fix available, CVSS 5.6
Timing Attack
SNYK-RUBY-RACK-20059
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Denial of Service (DoS)
SNYK-RUBY-RACK-20230
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Denial of Service (DoS)
SNYK-RUBY-RACK-20397
No No Known Exploit
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Arbitrary Code Injection
SNYK-RUBY-RACK-2848599
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-RACK-2848600
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-RACK-3356639
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Information Exposure
SNYK-RUBY-RACK-538324
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Directory Traversal
SNYK-RUBY-RACK-569066
Yes No Known Exploit
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Cross-site Request Forgery (CSRF)
SNYK-RUBY-RACK-572377
Yes Proof of Concept
medium severity 519/1000
Why? Has a fix available, CVSS 6.1
Cross-site Scripting (XSS)
SNYK-RUBY-RACK-72567
Yes No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Access Restriction Bypass
SNYK-RUBY-RAILS-472695
No No Known Exploit
high severity 579/1000
Why? Has a fix available, CVSS 7.3
SQL Injection
SNYK-RUBY-RAILS-472697
No No Known Exploit
medium severity 429/1000
Why? Has a fix available, CVSS 4.3
Cross-site Scripting (XSS)
SNYK-RUBY-RAILS-536099
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Timing Attack
SNYK-RUBY-RAILTIES-20454
Yes No Known Exploit
high severity 686/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
Arbitrary Code Injection
SNYK-RUBY-RAKE-552000
No Proof of Concept
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Directory Traversal
SNYK-RUBY-TZINFO-2958048
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: šŸ§ View latest project report

šŸ›  Adjust project settings

šŸ“š Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

šŸ¦‰ Denial of Service (DoS) šŸ¦‰ Cross-site Scripting (XSS) šŸ¦‰ Arbitrary Code Execution šŸ¦‰ More lessons are available in Snyk Learn