twilio / media-streams

Quick start guides for configuring and consuming Twilio Media Streams
100 stars 81 forks source link

[Snyk] Fix for 68 vulnerabilities #254

Open twilio-product-security opened 1 year ago

twilio-product-security commented 1 year ago

Snyk has created this PR to fix one or more vulnerable packages in the `rubygems` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Information Exposure
SNYK-RUBY-ACTIONPACK-1290051
No Proof of Concept
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-ACTIONPACK-1290052
No No Known Exploit
high severity 584/1000
Why? Has a fix available, CVSS 7.4
Information Exposure
SNYK-RUBY-ACTIONPACK-2400638
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ACTIONPACK-3237231
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ACTIONPACK-3237232
Yes No Known Exploit
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Cross-site Request Forgery (CSRF)
SNYK-RUBY-ACTIONPACK-569599
No Proof of Concept
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Information Exposure
SNYK-RUBY-ACTIONPACK-569600
No Proof of Concept
medium severity 591/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONVIEW-2803851
No Proof of Concept
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONVIEW-560837
No Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Cross-site Request Forgery (CSRF)
SNYK-RUBY-ACTIONVIEW-569601
No Proof of Concept
medium severity 449/1000
Why? Has a fix available, CVSS 4.7
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIONVIEW-632514
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ACTIVERECORD-1080913
No No Known Exploit
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Remote Code Execution (RCE)
SNYK-RUBY-ACTIVERECORD-2960802
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-ACTIVERECORD-3237239
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ACTIVESUPPORT-3237242
Yes No Known Exploit
medium severity 591/1000
Why? Recently disclosed, Has a fix available, CVSS 6.1
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIVESUPPORT-3360028
Yes No Known Exploit
high severity 834/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-RUBY-ACTIVESUPPORT-569598
No Mature
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ADDRESSABLE-1316242
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-GLOBALID-3237234
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-GOOGLEPROTOBUF-2331705
No No Known Exploit
medium severity 499/1000
Why? Has a fix available, CVSS 5.7
Denial of Service (DoS)
SNYK-RUBY-GOOGLEPROTOBUF-3040282
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-LOOFAH-3168317
No No Known Exploit
medium severity 519/1000
Why? Has a fix available, CVSS 6.1
Cross-site Scripting (XSS)
SNYK-RUBY-LOOFAH-3168318
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Uncontrolled Recursion
SNYK-RUBY-LOOFAH-3168649
No No Known Exploit
high severity 579/1000
Why? Has a fix available, CVSS 7.3
Cross-site Scripting (XSS)
SNYK-RUBY-LOOFAH-474102
No No Known Exploit
low severity 344/1000
Why? Has a fix available, CVSS 2.6
XML External Entity (XXE) Injection
SNYK-RUBY-NOKOGIRI-1055008
No No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-NOKOGIRI-1293239
No Proof of Concept
high severity 589/1000
Why? Has a fix available, CVSS 7.5
XML External Entity (XXE) Injection
SNYK-RUBY-NOKOGIRI-1726792
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Use After Free
SNYK-RUBY-NOKOGIRI-2413994
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-NOKOGIRI-2620374
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Out-of-bounds Write
SNYK-RUBY-NOKOGIRI-2630623
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-NOKOGIRI-2630898
No No Known Exploit
high severity 624/1000
Why? Has a fix available, CVSS 8.2
Improper Handling of Unexpected Data Type
SNYK-RUBY-NOKOGIRI-2840634
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
NULL Pointer Dereference
SNYK-RUBY-NOKOGIRI-3052880
No No Known Exploit
medium severity 414/1000
Why? Has a fix available, CVSS 4
Out-of-Bounds
SNYK-RUBY-NOKOGIRI-3357692
No No Known Exploit
high severity 659/1000
Why? Has a fix available, CVSS 8.9
Uncontrolled Memory Allocation
SNYK-RUBY-NOKOGIRI-534637
No No Known Exploit
high severity 600/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-NOKOGIRI-552159
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-PUMA-1291014
Yes No Known Exploit
low severity 399/1000
Why? Has a fix available, CVSS 3.7
HTTP Request Smuggling
SNYK-RUBY-PUMA-1730572
Yes No Known Exploit
high severity 614/1000
Why? Has a fix available, CVSS 8
Information Exposure
SNYK-RUBY-PUMA-2400629
Yes No Known Exploit
critical severity 669/1000
Why? Has a fix available, CVSS 9.1
HTTP Request Smuggling
SNYK-RUBY-PUMA-2437090
Yes No Known Exploit
high severity 624/1000
Why? Has a fix available, CVSS 8.2
Denial of Service (DoS)
SNYK-RUBY-PUMA-536835
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
HTTP Response Splitting
SNYK-RUBY-PUMA-559020
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
HTTP Response Splitting
SNYK-RUBY-PUMA-559100
No No Known Exploit
medium severity 550/1000
Why? Has a fix available, CVSS 6.5
HTTP Request Smuggling
SNYK-RUBY-PUMA-570205
No No Known Exploit
medium severity 550/1000
Why? Has a fix available, CVSS 6.5
HTTP Request Smuggling
SNYK-RUBY-PUMA-570206
No No Known Exploit
medium severity 616/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.9
Web Cache Poisoning
SNYK-RUBY-RACK-1061917
Yes Proof of Concept
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Arbitrary Code Injection
SNYK-RUBY-RACK-2848599
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-RACK-2848600
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-RACK-3237233
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-RACK-3237237
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-RACK-3237240
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-RACK-3356639
No No Known Exploit
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-RACK-3360233
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Information Exposure
SNYK-RUBY-RACK-538324
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Directory Traversal
SNYK-RUBY-RACK-569066
No No Known Exploit
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Cross-site Request Forgery (CSRF)
SNYK-RUBY-RACK-572377
No Proof of Concept
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-RAILS-1071903
No Proof of Concept
medium severity 611/1000
Why? Recently disclosed, Has a fix available, CVSS 6.5
Cross-site Scripting (XSS)
SNYK-RUBY-RAILS-5291540
Yes No Known Exploit
medium severity 531/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 4.2
Cross-site Scripting (XSS)
SNYK-RUBY-RAILSHTMLSANITIZER-2935879
No Proof of Concept
medium severity 484/1000
Why? Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-RUBY-RAILSHTMLSANITIZER-3168316
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-RAILSHTMLSANITIZER-3168646
No No Known Exploit
medium severity 626/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.1
Cross-site Scripting (XSS)
SNYK-RUBY-RAILSHTMLSANITIZER-3168647
No Proof of Concept
medium severity 424/1000
Why? Has a fix available, CVSS 4.2
Cross-site Scripting (XSS)
SNYK-RUBY-RAILSHTMLSANITIZER-3168648
No No Known Exploit
high severity 686/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
Arbitrary Code Injection
SNYK-RUBY-RAKE-552000
No Proof of Concept
high severity 635/1000
Why? Has a fix available, CVSS 8.2
Denial of Service (DoS)
SNYK-RUBY-RUBYZIP-469156
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Directory Traversal
SNYK-RUBY-TZINFO-2958048
No No Known Exploit
high severity 731/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.2
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-WEBSOCKETEXTENSIONS-570830
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Denial of Service (DoS) 🦉 Cross-site Request Forgery (CSRF) 🦉 Cross-site Scripting (XSS) 🦉 More lessons are available in Snyk Learn