rubygem-rack

Direct Vulnerabilities

Known vulnerabilities in the rubygem-rack package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Cross-site Scripting (XSS)

*
  • H
Resource Exhaustion

*
  • M
HTTP Request Smuggling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Insufficient Session Expiration

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Directory Traversal

*
  • H
Directory Traversal

*
  • M
Improper Output Neutralization for Logs

*
  • M
Improper Output Neutralization for Logs

*
  • M
Improper Output Neutralization for Logs

*
  • M
Improper Output Neutralization for Logs

*
  • M
Reliance on Untrusted Inputs in a Security Decision

<1:1.6.12-1.el7sat
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Information Exposure Through Log Files

<1:1.6.4-3.el7sat
  • M
Cross-site Scripting (XSS)

<1:1.6.4-3.el7sat
  • M
Cross-site Scripting (XSS)

<1:1.6.4-3.el7sat
  • M
Cross-site Scripting (XSS)

<1:1.6.4-3.el7sat
  • M
Information Exposure

<1:1.6.12-1.el7sat
  • M
Missing Authorization

<1:1.6.12-1.el7sat
  • M
Information Exposure Through Log Files

<1:1.6.12-1.el7sat
  • H
Information Exposure

<1:1.6.4-3.el7sat
  • H
SQL Injection

<1:1.6.4-3.el7sat
  • H
Information Exposure

<1:1.6.4-3.el7sat
  • H
Deserialization of Untrusted Data

<1:1.6.4-3.el7sat
  • H
Cross-site Scripting (XSS)

<1:1.6.4-3.el7sat
  • H
Cross-site Scripting (XSS)

<1:1.6.4-3.el7sat
  • H
Information Exposure

<1:1.6.4-3.el7sat
  • H
Improper Input Validation

<1:1.6.12-1.el7sat
  • H
Use of a Broken or Risky Cryptographic Algorithm

<1:1.6.4-3.el7sat
  • H
Cross-site Scripting (XSS)

<1:1.6.12-1.el7sat
  • H
Improper Access Control

<1:1.6.4-3.el7sat
  • H
Missing Required Cryptographic Step

<1:1.6.4-3.el7sat
  • H
Missing Required Cryptographic Step

<1:1.6.4-3.el7sat
  • H
Information Exposure

<1:1.6.4-3.el7sat
  • H
Covert Timing Channel

<1:1.6.4-3.el7sat
  • H
Incorrect Calculation

<1:1.6.4-3.el7sat
  • H
Missing Required Cryptographic Step

<1:1.6.4-3.el7sat
  • H
Missing Required Cryptographic Step

<1:1.6.4-3.el7sat
  • H
Missing Required Cryptographic Step

<1:1.6.4-3.el7sat
  • M
Information Exposure

<1:1.6.12-1.el7sat
  • M
Directory Traversal

<1:1.6.4-3.el7sat
  • M
Inefficient Regular Expression Complexity

*
  • H
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

<1:1.6.4-3.el7sat
  • H
Improper Certificate Validation

<1:1.6.4-3.el7sat
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
CVE-2013-6668

<1:1.6.4-2.el7sat
  • M
Information Exposure

<1:1.4.1-13.el7sat
  • M
Improper Input Validation

<1:1.4.1-13.el7sat
  • M
Incorrect Permission Assignment for Critical Resource

<1:1.6.4-3.el7sat
  • M
Cleartext Storage of Sensitive Information

<1:1.6.4-3.el7sat
  • M
Improper Authentication

<1:1.6.4-3.el7sat
  • H
Information Exposure

<1:1.6.4-3.el7sat
  • H
Improper Authorization

<1:1.6.4-3.el7sat
  • H
Cleartext Transmission of Sensitive Information

<1:1.6.4-3.el7sat
  • H
Improper Certificate Validation

<1:1.6.4-3.el7sat
  • H
Insufficiently Protected Credentials

<1:1.6.12-1.el7sat
  • H
Inefficient Regular Expression Complexity

<1:1.6.4-3.el7sat
  • H
Inefficient Regular Expression Complexity

<1:1.6.4-3.el7sat
  • H
Cross-site Scripting (XSS)

<1:1.6.4-3.el7sat
  • H
Improper Authentication

<1:1.6.12-1.el7sat
  • M
Cross-site Scripting (XSS)

<1:1.6.4-3.el7sat
  • M
Information Exposure

*
  • H
Information Exposure

<1:1.6.12-1.el7sat
  • M
Information Exposure

<1:1.6.12-1.el7sat
  • M
Information Exposure

*
  • H
Binding to an Unrestricted IP Address

<1:1.6.12-1.el7sat
  • M
SQL Injection

<1:1.6.12-1.el7sat
  • H
Improperly Implemented Security Check for Standard

<1:1.6.12-1.el7sat
  • H
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

<1:1.6.4-3.el7sat
  • H
Directory Traversal

<0:2.2.4-1.el7rhgs
  • H
Missing Authorization

<1:1.6.12-1.el7sat
  • M
Omission of Security-relevant Information

<1:1.6.4-2.el7sat
  • H
Information Exposure

<1:1.6.4-3.el7sat
  • H
Improper Validation of Certificate with Host Mismatch

<1:1.6.12-1.el7sat
  • M
Execution with Unnecessary Privileges

<1:1.6.12-1.el7sat
  • H
HTTP Request Smuggling

<1:1.6.12-1.el7sat
  • M
Cross-site Scripting (XSS)

*
  • H
HTTP Request Smuggling

<0:2.2.4-1.el7rhgs
  • M
Resource Exhaustion

<1:1.6.4-3.el7sat
  • M
Allocation of Resources Without Limits or Throttling

<1:1.6.12-1.el7sat
  • M
Information Exposure

<1:1.6.12-1.el7sat
  • M
Cross-site Request Forgery (CSRF)

<1:1.6.12-1.el7sat
  • H
Cross-site Scripting (XSS)

<1:1.6.12-1.el7sat
  • M
Cross-site Request Forgery (CSRF)

<1:1.6.12-1.el7sat
  • H
Inefficient Regular Expression Complexity

<1:1.6.12-1.el7sat
  • M
Cross-site Scripting (XSS)

<1:1.6.12-1.el7sat
  • M
Improper Input Validation

<1:1.6.12-1.el7sat
  • M
Improper Input Validation

<1:1.6.12-1.el7sat
  • H
Arbitrary Code Injection

<1:1.6.12-1.el7sat
  • L
Directory Traversal

*
  • H
Directory Traversal

<1:1.6.12-1.el7sat
  • L
Directory Traversal

*
  • M
Directory Traversal

*
  • H
CRLF Injection

<1:1.6.12-1.el7sat
  • H
Incomplete Blacklist

<1:1.6.4-3.el7sat
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • H
Resource Exhaustion

<0:2.2.4-1.el7rhgs
  • H
Incorrect Behavior Order: Early Validation

*
  • L
Incorrect Behavior Order: Early Validation

*
  • H
Incorrect Behavior Order: Early Validation

<0:2.2.4-1.el7rhgs
  • H
Allocation of Resources Without Limits or Throttling

<0:2.2.4-1.el7rhgs
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Reliance on Untrusted Inputs in a Security Decision

*
  • H
Reliance on Untrusted Inputs in a Security Decision

<1:1.6.12-1.el7sat
  • M
Reliance on Untrusted Inputs in a Security Decision

*
  • M
Resource Exhaustion

<1:1.6.4-2.el7sat
  • M
HTTP Response Splitting

<1:1.6.4-3.el7sat
  • H
CVE-2018-3258

<1:1.6.12-1.el7sat
  • H
Covert Timing Channel

<1:1.6.12-1.el7sat
  • M
Covert Timing Channel

<1:1.6.12-1.el7sat
  • M
Arbitrary Argument Injection

<1:1.6.4-3.el7sat
  • H
Out-of-Bounds

<1:1.6.4-3.el7sat
  • M
Improper Neutralization of Special Elements

<1:1.6.4-3.el7sat
  • H
Deserialization of Untrusted Data

<1:1.6.4-3.el7sat
  • M
CVE-2016-6346

<1:1.6.4-3.el7sat
  • H
Deserialization of Untrusted Data

<1:1.6.12-1.el7sat
  • H
Deserialization of Untrusted Data

<1:1.6.12-1.el7sat
  • H
Deserialization of Untrusted Data

<1:1.6.12-1.el7sat
  • H
Deserialization of Untrusted Data

<1:1.6.12-1.el7sat
  • M
Improper Neutralization of Special Elements

<1:1.6.4-3.el7sat
  • M
Information Exposure

<1:1.6.12-1.el7sat
  • H
Deserialization of Untrusted Data

<1:1.6.12-1.el7sat
  • H
Deserialization of Untrusted Data

<1:1.6.12-1.el7sat
  • H
Deserialization of Untrusted Data

<1:1.6.12-1.el7sat
  • M
Access Restriction Bypass

<1:1.4.1-13.el7sat
  • M
Improper Data Handling

<1:1.4.1-13.el7sat
  • M
Improper Data Handling

<1:1.4.1-13.el7sat
  • H
Deserialization of Untrusted Data

<1:1.6.12-1.el7sat
  • H
Deserialization of Untrusted Data

<1:1.6.12-1.el7sat
  • H
Deserialization of Untrusted Data

<1:1.6.12-1.el7sat
  • M
Use After Free

<1:1.6.12-1.el7sat
  • H
Deserialization of Untrusted Data

<1:1.6.4-3.el7sat
  • M
Algorithmic Complexity

<1:1.4.1-13.el7sat