Skip to content

Instantly share code, notes, and snippets.

@will
Last active August 29, 2015 14:23
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save will/e12a3af8091753284fe4 to your computer and use it in GitHub Desktop.
Save will/e12a3af8091753284fe4 to your computer and use it in GitHub Desktop.
5 Rails CVEs

[CVE-2015-3225] Potential Denial of Service Vulnerability in Rack https://groups.google.com/d/msg/rubyonrails-security/gcUbICUmKMc/qiCotVZwXrMJ

[CVE-2015-1840] CSRF Vulnerability in jquery-ujs and jquery-rails https://groups.google.com/d/msg/rubyonrails-security/XIZPbobuwaY/fqnzzpuOlA4J

[CVE-2015-3226] XSS Vulnerability in ActiveSupport::JSON.encode https://groups.google.com/d/msg/rubyonrails-security/7VlB_pck3hU/3QZrGIaQW6cJ

[CVE-2015-3224] IP whitelist bypass in Web Console https://groups.google.com/d/msg/rubyonrails-security/lzmz9_ijUFw/HBMPi4zp5NAJ

[CVE-2015-3227] Possible Denial of Service attack in Active Support https://gist.github.com/tenderlove/f2a606459f6027f583c9

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment