Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Rubyonrails Subscribe
Filtered by product Actionpack
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-22577 2 Debian, Rubyonrails 2 Debian Linux, Actionpack 2023-03-14 4.3 MEDIUM 6.1 MEDIUM
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.
CVE-2022-27777 2 Debian, Rubyonrails 2 Debian Linux, Actionpack 2023-03-14 4.3 MEDIUM 6.1 MEDIUM
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes.