addon-template icon indicating copy to clipboard operation
addon-template copied to clipboard

[Snyk] Fix for 59 vulnerabilities

Open svc-ast-gh-snyk2 opened this issue 1 year ago • 0 comments

Snyk has created this PR to fix one or more vulnerable packages in the `rubygems` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • Gemfile
⚠️ Warning
Failed to update the Gemfile.lock, please update manually before merging.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ACTIVESUPPORT-3237242
No No Known Exploit
medium severity 591/1000
Why? Recently disclosed, Has a fix available, CVSS 6.1
Cross-site Scripting (XSS)
SNYK-RUBY-ACTIVESUPPORT-3360028
No No Known Exploit
high severity 834/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-RUBY-ACTIVESUPPORT-569598
No Mature
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ADDRESSABLE-1316242
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-I18N-72582
No No Known Exploit
critical severity 679/1000
Why? Has a fix available, CVSS 9.3
Denial of Service (DoS)
SNYK-RUBY-JSON-560838
No No Known Exploit
high severity 584/1000
Why? Has a fix available, CVSS 7.4
Command Injection
SNYK-RUBY-MECHANIZE-1069888
No No Known Exploit
low severity 399/1000
Why? Has a fix available, CVSS 3.7
Information Exposure
SNYK-RUBY-MECHANIZE-20364
No No Known Exploit
low severity 344/1000
Why? Has a fix available, CVSS 2.6
XML External Entity (XXE) Injection
SNYK-RUBY-NOKOGIRI-1055008
No No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-NOKOGIRI-1293239
No Proof of Concept
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
Denial of Service (DoS)
SNYK-RUBY-NOKOGIRI-1583442
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
XML External Entity (XXE) Injection
SNYK-RUBY-NOKOGIRI-1726792
No No Known Exploit
high severity 579/1000
Why? Has a fix available, CVSS 7.3
XML External Entity (XXE) Injection
SNYK-RUBY-NOKOGIRI-20299
No No Known Exploit
high severity 654/1000
Why? Has a fix available, CVSS 8.8
Arbitrary Code Execution
SNYK-RUBY-NOKOGIRI-20367
No No Known Exploit
high severity 654/1000
Why? Has a fix available, CVSS 8.8
Out of Bounds Memory Write
SNYK-RUBY-NOKOGIRI-20368
No No Known Exploit
high severity 826/1000
Why? Mature exploit, Has a fix available, CVSS 8.8
Use of vulnerable libxml2
SNYK-RUBY-NOKOGIRI-20432
No Mature
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-NOKOGIRI-22013
No No Known Exploit
high severity 654/1000
Why? Has a fix available, CVSS 8.8
Denial of Service (DoS)
SNYK-RUBY-NOKOGIRI-22014
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Use After Free
SNYK-RUBY-NOKOGIRI-2413994
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-NOKOGIRI-2620374
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Out-of-bounds Write
SNYK-RUBY-NOKOGIRI-2630623
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-NOKOGIRI-2630898
No No Known Exploit
high severity 624/1000
Why? Has a fix available, CVSS 8.2
Improper Handling of Unexpected Data Type
SNYK-RUBY-NOKOGIRI-2840634
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
NULL Pointer Dereference
SNYK-RUBY-NOKOGIRI-3052880
No No Known Exploit
medium severity 414/1000
Why? Has a fix available, CVSS 4
Out-of-Bounds
SNYK-RUBY-NOKOGIRI-3357692
No No Known Exploit
medium severity 529/1000
Why? Has a fix available, CVSS 6.3
Access Control Bypass
SNYK-RUBY-NOKOGIRI-3357693
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Command Injection
SNYK-RUBY-NOKOGIRI-459107
No No Known Exploit
high severity 659/1000
Why? Has a fix available, CVSS 8.9
Uncontrolled Memory Allocation
SNYK-RUBY-NOKOGIRI-534637
No No Known Exploit
high severity 600/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-NOKOGIRI-552159
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-NOKOGIRI-72433
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-PUMA-1291014
Yes No Known Exploit
low severity 399/1000
Why? Has a fix available, CVSS 3.7
HTTP Request Smuggling
SNYK-RUBY-PUMA-1730572
Yes No Known Exploit
high severity 614/1000
Why? Has a fix available, CVSS 8
Information Exposure
SNYK-RUBY-PUMA-2400629
Yes No Known Exploit
critical severity 669/1000
Why? Has a fix available, CVSS 9.1
HTTP Request Smuggling
SNYK-RUBY-PUMA-2437090
Yes No Known Exploit
high severity 624/1000
Why? Has a fix available, CVSS 8.2
Denial of Service (DoS)
SNYK-RUBY-PUMA-536835
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
HTTP Response Splitting
SNYK-RUBY-PUMA-559020
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
HTTP Response Splitting
SNYK-RUBY-PUMA-559100
No No Known Exploit
medium severity 550/1000
Why? Has a fix available, CVSS 6.5
HTTP Request Smuggling
SNYK-RUBY-PUMA-570205
No No Known Exploit
medium severity 550/1000
Why? Has a fix available, CVSS 6.5
HTTP Request Smuggling
SNYK-RUBY-PUMA-570206
No No Known Exploit
medium severity 616/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.9
Web Cache Poisoning
SNYK-RUBY-RACK-1061917
No Proof of Concept
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Arbitrary Code Injection
SNYK-RUBY-RACK-2848599
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-RACK-2848600
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-RACK-3237240
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-RACK-3356639
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Information Exposure
SNYK-RUBY-RACK-538324
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Directory Traversal
SNYK-RUBY-RACK-569066
Yes No Known Exploit
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Cross-site Request Forgery (CSRF)
SNYK-RUBY-RACK-572377
Yes Proof of Concept
medium severity 519/1000
Why? Has a fix available, CVSS 6.1
Cross-site Scripting (XSS)
SNYK-RUBY-RACK-72567
No No Known Exploit
low severity 399/1000
Why? Has a fix available, CVSS 3.7
Side-channel attack
SNYK-RUBY-RACKPROTECTION-20394
Yes No Known Exploit
medium severity 509/1000
Why? Has a fix available, CVSS 5.9
Timing Attack
SNYK-RUBY-RACKPROTECTION-20395
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Directory Traversal
SNYK-RUBY-RACKPROTECTION-22019
No No Known Exploit
high severity 686/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
Arbitrary Code Injection
SNYK-RUBY-RAKE-552000
Yes Proof of Concept
medium severity 509/1000
Why? Has a fix available, CVSS 5.9
Timing Attack
SNYK-RUBY-SINATRA-20488
Yes No Known Exploit
medium severity 519/1000
Why? Has a fix available, CVSS 6.1
Cross-site Scripting (XSS)
SNYK-RUBY-SINATRA-22027
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Improper Input Validation
SNYK-RUBY-SINATRA-2806372
Yes No Known Exploit
high severity 654/1000
Why? Has a fix available, CVSS 8.8
Resources Downloaded over Insecure Protocol
SNYK-RUBY-SINATRA-3150405
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Directory Traversal
SNYK-RUBY-TZINFO-2958048
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Directory Traversal
SNYK-RUBY-YARD-22004
No No Known Exploit
high severity 624/1000
Why? Has a fix available, CVSS 8.2
Directory Traversal
SNYK-RUBY-YARD-455636
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS) 🦉 Cross-site Scripting (XSS) 🦉 Deserialization of Untrusted Data 🦉 More lessons are available in Snyk Learn

svc-ast-gh-snyk2 avatar Apr 05 '23 02:04 svc-ast-gh-snyk2