Rubyonrails
Rubyonrails Rails: vulnerabilidades y CVE
Rubyonrails Rails tiene 121 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 4 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE121
Últimos 12 meses9
Críticas4
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-5418 | Alta (7.5) | 99% | ⚠ Explotación activa | 27 mar 2019 | There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's… |
| CVE-2014-0130 | Alta (7.5) | 54% | ⚠ Explotación activa | 7 may 2014 | Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route… |
| CVE-2016-0752 | Alta (7.5) | 96% | ⚠ Explotación activa | 16 feb 2016 | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-33658 | Baja (2.3) | 0.57% | — | 26 mar 2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP… |
| CVE-2026-33202 | Media (6.6) | 0.78% | — | 24 mar 2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob`… |
| CVE-2026-33195 | Alta (8) | 0.72% | — | 24 mar 2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem… |
| CVE-2026-33176 | Media (6.6) | 0.97% | — | 24 mar 2026 | Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing… |
| CVE-2026-33174 | Media (6.6) | 0.70% | — | 24 mar 2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active Storage's proxy delivery mode, the proxy controller… |
| CVE-2026-33173 | Media (5.3) | 0.43% | — | 24 mar 2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsController` accepts arbitrary metadata from the client and persists it on… |
| CVE-2026-33170 | Media (5.3) | 0.43% | — | 24 mar 2026 | Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `SafeBuffer#%` does not propagate the `@html_unsafe` flag to… |
| CVE-2026-33169 | Media (6.9) | 0.59% | — | 24 mar 2026 | Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a lookahead-based regular expression with `gsub!` to insert thousands… |
| CVE-2026-33167 | Baja (1.3) | 0.33% | — | 23 mar 2026 | Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted… |
| CVE-2025-57821 | Media (4.2) | 0.24% | — | 27 ago 2025 | Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.0, it is possible to craft a malformed URL that passes the "same origin" check, resulting in the user being redirected to another… |
| CVE-2023-28362 | Media (4) | 0.33% | — | 9 ene 2025 | The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP… |
| CVE-2024-41961 | Crítica (9.6) | 0.62% | — | 1 ago 2024 | Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web… |
| CVE-2024-32464 | Media (6.1) | 0.43% | — | 4 jun 2024 | Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area tag could potentially contain unsanitized HTML. This vulnerability is… |
| CVE-2024-28103 | Crítica (9.8) | 0.66% | — | 4 jun 2024 | Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is… |
| CVE-2024-26144 | Media (5.3) | 1.1% | — | 27 feb 2024 | Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's… |
| CVE-2024-26143 | Media (6.1) | 1.0% | — | 27 feb 2024 | Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a… |
| CVE-2024-26142 | Alta (7.5) | 1.5% | — | 27 feb 2024 | Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has… |
| CVE-2023-22797 | Media (6.1) | 0.60% | — | 9 feb 2023 | An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only… |
| CVE-2023-22795 | Alta (7.5) | 2.3% | — | 9 feb 2023 | A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP If-None-Match header can cause the regular expression engine to enter a… |
| CVE-2023-22792 | Alta (7.5) | 1.7% | — | 9 feb 2023 | A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cookies, in combination with a specially crafted X_FORWARDED_HOST header can cause the regular… |
| CVE-2022-3704 | Media (5.4) | 0.75% | — | 26 oct 2022 | A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/middleware/templates/routes/_table.html.erb. The manipulation leads to… |
| CVE-2022-23634 | Media (5.9) | 2.1% | — | 11 feb 2022 | Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being… |
| CVE-2022-23633 | Media (5.9) | 2.2% | — | 11 feb 2022 | Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor`… |
| CVE-2021-44528 | Media (6.1) | 4.2% | — | 10 ene 2022 | A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization… |
| CVE-2011-1497 | Media (6.1) | 1.3% | — | 19 oct 2021 | A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6. |
| CVE-2021-22942 | Media (6.1) | 1.7% | — | 18 oct 2021 | A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website. |
| CVE-2021-22904 | Alta (7.5) | 5.0% | — | 11 jun 2021 | The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression.… |
| CVE-2021-22903 | Media (6.1) | 1.2% | — | 11 jun 2021 | The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware… |
| CVE-2021-22902 | Alta (7.5) | 2.8% | — | 11 jun 2021 | The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch.… |
| CVE-2021-22885 | Alta (7.5) | 4.1% | — | 27 may 2021 | A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.