RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2015-7519Lowpassenger: Phusion Passenger allows remote attackers to spoof headersCVE-2018-14643Criticalsmart_proxy_dynflow: smart_proxy_dynflow gem authentication bypass in Foreman remote execution featureCVE-2018-17567Highjekyll: Jekyll allows attackers to access arbitrary files by specifying a symlinkCVE-2015-7499Mediumnokogiri: Heap-based buffer overflow in nokogiriCVE-2014-8144Mediumdoorkeeper: Doorkeeper vulnerable to Cross-site Request ForgeryCVE-2015-8806Highnokogiri: Denial of service or RCE from libxml2 and libxsltCVE-2018-14042Mediumbootstrap: Bootstrap Cross-site Scripting vulnerabilityCVE-2018-14041Mediumbootstrap: Bootstrap Cross-site Scripting vulnerabilityCVE-2018-1000544Criticalrubyzip: Rubyzip gem contains a Directory Traversal vulnerability in zip file componentCVE-2018-1000201Highffi: Ruby-ffi has a DLL loading issue CVE-2015-1866Mediumember-source: ember-source vulnerable to Cross-site ScriptingCVE-2015-4619Highspina: Spina gem vulnerable to Cross-site request forgery (CSRF) vulnerabilityCVE-2015-7225Mediumdevise-two-factor: Tinfoil Devise-two-factor does not "burn" a successfully validated one-time password (OTP)CVE-2015-7314Mediumgollum: Gollum Exposure of Sensitive InformationCVE-2014-0046Lowember-source: ember-source Cross-site Scripting vulnerabilityCVE-2015-7565Mediumember-source: ember-source Cross-site Scripting vulnerabilityCVE-2016-4658Criticalnokogiri: Nokogiri does not forbid namespace nodes in XPointer rangesCVE-2015-5312Highnokogiri: Nokogiri subject to DoS via libxml2 vulnerabilityCVE-2016-5697Highruby-saml: Ruby-saml allows attackers to perform XML signature wrapping attacks CVE-2016-10345Highpassenger: Phusion Passenger uses a known /tmp filenameCVE-2015-8969Criticalgit-fastclone: Git-fastclone passes user modifiable strings directly to a shell commandCVE-2015-5147Highredcarpet: redcarpet Buffer Overflow vulnerabilityCVE-2015-8968Highgit-fastclone: git-fastclone permits arbitrary shell command execution from .gitmodulesCVE-2015-1820Criticalrest-client: rest-client Gem Vulnerable to Session FixationCVE-2018-1000211Highdoorkeeper: Doorkeeper subject to Incorrect Permission Assignment

Stop the waste.
Protect your environment with Kodem.