Vulnerabilities (CVE)

Filtered by vendor Rubyonrails Subscribe
Filtered by product Actionpack
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-22577 1 Rubyonrails 1 Actionpack 2022-06-07 4.3 MEDIUM 6.1 MEDIUM
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.
CVE-2022-27777 1 Rubyonrails 1 Actionpack 2022-06-07 4.3 MEDIUM 6.1 MEDIUM
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes.