gruz0 / inspirer-web

Inspirer Web
3 stars 1 forks source link

[Snyk] Fix for 36 vulnerabilities #630

Open snyk-bot opened 1 year ago

snyk-bot commented 1 year ago

Snyk has created this PR to fix one or more vulnerable packages in the `rubygems` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 579/1000
Why? Has a fix available, CVSS 7.3
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONPACK-1016639
No No Known Exploit
medium severity 484/1000
Why? Has a fix available, CVSS 5.4
Open Redirect
SNYK-RUBY-ACTIONPACK-1080916
No No Known Exploit
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Information Exposure
SNYK-RUBY-ACTIONPACK-1290051
No Proof of Concept
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-ACTIONPACK-1290052
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ACTIONPACK-1290053
No No Known Exploit
medium severity 519/1000
Why? Has a fix available, CVSS 6.1
Open Redirect
SNYK-RUBY-ACTIONPACK-2320175
No No Known Exploit
high severity 584/1000
Why? Has a fix available, CVSS 7.4
Information Exposure
SNYK-RUBY-ACTIONPACK-2400638
No No Known Exploit
medium severity 484/1000
Why? Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONPACK-2803847
No No Known Exploit
medium severity 591/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONVIEW-2803851
No Proof of Concept
medium severity 449/1000
Why? Has a fix available, CVSS 4.7
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONVIEW-632514
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ACTIVERECORD-1080913
No No Known Exploit
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Remote Code Execution (RCE)
SNYK-RUBY-ACTIVERECORD-2960802
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Arbitrary Code Injection
SNYK-RUBY-ACTIVESTORAGE-2420035
No Proof of Concept
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ADDRESSABLE-1316242
No No Known Exploit
medium severity 529/1000
Why? Has a fix available, CVSS 6.3
Cross-site Request Forgery (CSRF)
SNYK-RUBY-BETTERERRORS-1583446
No No Known Exploit
low severity 344/1000
Why? Has a fix available, CVSS 2.6
XML External Entity (XXE) Injection
SNYK-RUBY-NOKOGIRI-1055008
No No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-NOKOGIRI-1293239
No Proof of Concept
high severity 589/1000
Why? Has a fix available, CVSS 7.5
XML External Entity (XXE) Injection
SNYK-RUBY-NOKOGIRI-1726792
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Use After Free
SNYK-RUBY-NOKOGIRI-2413994
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-NOKOGIRI-2620374
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Out-of-bounds Write
SNYK-RUBY-NOKOGIRI-2630623
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-NOKOGIRI-2630898
No No Known Exploit
high severity 624/1000
Why? Has a fix available, CVSS 8.2
Improper Handling of Unexpected Data Type
SNYK-RUBY-NOKOGIRI-2840634
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-PUMA-1291014
No No Known Exploit
low severity 399/1000
Why? Has a fix available, CVSS 3.7
HTTP Request Smuggling
SNYK-RUBY-PUMA-1730572
No No Known Exploit
high severity 614/1000
Why? Has a fix available, CVSS 8
Information Exposure
SNYK-RUBY-PUMA-2400629
No No Known Exploit
critical severity 669/1000
Why? Has a fix available, CVSS 9.1
HTTP Request Smuggling
SNYK-RUBY-PUMA-2437090
No No Known Exploit
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Arbitrary Code Injection
SNYK-RUBY-RACK-2848599
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-RACK-2848600
No No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-RAILS-1071903
No Proof of Concept
high severity 594/1000
Why? Has a fix available, CVSS 7.6
Open Redirect
SNYK-RUBY-RAILS-1567785
No No Known Exploit
medium severity 531/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 4.2
Cross-site Scripting (XSS)
SNYK-RUBY-RAILSHTMLSANITIZER-2935879
No Proof of Concept
medium severity 484/1000
Why? Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-RUBY-SIDEKIQ-1090607
No No Known Exploit
medium severity 484/1000
Why? Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-RUBY-SIDEKIQ-1729733
No No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-SIDEKIQ-2359050
No Proof of Concept
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Directory Traversal
SNYK-RUBY-TZINFO-2958048
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Directory Traversal 🦉 Denial of Service (DoS) 🦉 Cross-site Scripting (XSS) 🦉 More lessons are available in Snyk Learn