hurl2
hurl2 copied to clipboard
[Snyk] Fix for 26 vulnerabilities
Snyk has created this PR to fix one or more vulnerable packages in the `rubygems` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- Gemfile
- Gemfile.lock
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 579/1000 Why? Has a fix available, CVSS 7.3 |
Denial of Service (DoS) SNYK-RUBY-JSON-20060 |
No | No Known Exploit | |
| 679/1000 Why? Has a fix available, CVSS 9.3 |
Denial of Service (DoS) SNYK-RUBY-JSON-560838 |
No | No Known Exploit | |
| 616/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 5.9 |
Web Cache Poisoning SNYK-RUBY-RACK-1061917 |
No | Proof of Concept | |
| 479/1000 Why? Has a fix available, CVSS 5.3 |
Denial of Service (DoS) SNYK-RUBY-RACK-20021 |
No | No Known Exploit | |
| 429/1000 Why? Has a fix available, CVSS 4.3 |
Regular Expression Denial of Service (ReDoS) SNYK-RUBY-RACK-20028 |
No | No Known Exploit | |
| 479/1000 Why? Has a fix available, CVSS 5.3 |
Denial of Service (DoS) SNYK-RUBY-RACK-20045 |
No | No Known Exploit | |
| 429/1000 Why? Has a fix available, CVSS 4.3 |
Denial of Service (DoS) SNYK-RUBY-RACK-20052 |
No | No Known Exploit | |
| 536/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 4.3 |
Arbitrary File Disclosure SNYK-RUBY-RACK-20058 |
No | Proof of Concept | |
| 494/1000 Why? Has a fix available, CVSS 5.6 |
Timing Attack SNYK-RUBY-RACK-20059 |
No | No Known Exploit | |
| 479/1000 Why? Has a fix available, CVSS 5.3 |
Denial of Service (DoS) SNYK-RUBY-RACK-20230 |
No | No Known Exploit | |
| 479/1000 Why? Has a fix available, CVSS 5.3 |
Denial of Service (DoS) SNYK-RUBY-RACK-20397 |
No | No Known Exploit | |
| 704/1000 Why? Has a fix available, CVSS 9.8 |
Arbitrary Code Injection SNYK-RUBY-RACK-2848599 |
Yes | No Known Exploit | |
| 589/1000 Why? Has a fix available, CVSS 7.5 |
Denial of Service (DoS) SNYK-RUBY-RACK-2848600 |
Yes | No Known Exploit | |
| 589/1000 Why? Has a fix available, CVSS 7.5 |
Denial of Service (DoS) SNYK-RUBY-RACK-3356639 |
Yes | No Known Exploit | |
| 479/1000 Why? Has a fix available, CVSS 5.3 |
Information Exposure SNYK-RUBY-RACK-538324 |
No | No Known Exploit | |
| 589/1000 Why? Has a fix available, CVSS 7.5 |
Directory Traversal SNYK-RUBY-RACK-569066 |
Yes | No Known Exploit | |
| 646/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 6.5 |
Cross-site Request Forgery (CSRF) SNYK-RUBY-RACK-572377 |
Yes | Proof of Concept | |
| 519/1000 Why? Has a fix available, CVSS 6.1 |
Cross-site Scripting (XSS) SNYK-RUBY-RACK-72567 |
No | No Known Exploit | |
| 414/1000 Why? Has a fix available, CVSS 4 |
Local Plaintext Password Disclosure SNYK-RUBY-RESTCLIENT-20204 |
No | No Known Exploit | |
| 484/1000 Why? Has a fix available, CVSS 5.4 |
Session Fixation SNYK-RUBY-SINATRA-20468 |
No | No Known Exploit | |
| 509/1000 Why? Has a fix available, CVSS 5.9 |
Timing Attack SNYK-RUBY-SINATRA-20488 |
Yes | No Known Exploit | |
| 519/1000 Why? Has a fix available, CVSS 6.1 |
Cross-site Scripting (XSS) SNYK-RUBY-SINATRA-22027 |
Yes | No Known Exploit | |
| 589/1000 Why? Has a fix available, CVSS 7.5 |
Improper Input Validation SNYK-RUBY-SINATRA-2806372 |
Yes | No Known Exploit | |
| 654/1000 Why? Has a fix available, CVSS 8.8 |
Resources Downloaded over Insecure Protocol SNYK-RUBY-SINATRA-3150405 |
Yes | No Known Exploit | |
| 589/1000 Why? Has a fix available, CVSS 7.5 |
Denial of Service (DoS) SNYK-RUBY-YAJLRUBY-22002 |
No | No Known Exploit | |
| 509/1000 Why? Has a fix available, CVSS 5.9 |
Denial of Service (DoS) SNYK-RUBY-YAJLRUBY-2441253 |
No | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Denial of Service (DoS) 🦉 Arbitrary Code Injection 🦉 Directory Traversal 🦉 More lessons are available in Snyk Learn