Packages you depend on that have known security holes (CVEs).
-
Serious CVE-2020-8165 rubygem-activesupport: potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2020-8165). Fix: Update that package to its patched version.
-
Serious CVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2020-14001). Fix: Update that package to its patched version.
-
Serious CVE-2022-30123 rubygem-rack: crafted requests can cause shell escape sequences
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2022-30123). Fix: Update that package to its patched version.
-
Serious CVE-2015-8857 The uglify-js package before 2.4.24 for Node.js does not properly acco ...
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2015-8857). Fix: Update that package to its patched version.
-
Worth fixing CVE-2023-22796 rubygem-activesupport: Regular Expression Denial of Service
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2023-22796). Fix: Update that package to its patched version.
-
Worth fixing CVE-2026-33176 Rails: Active Support: Active Support: Denial of Service via large scientific notation strings
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2026-33176). Fix: Update that package to its patched version.
-
Worth fixing CVE-2023-28120 rubygem-activesupport: Possible XSS in SafeBuffer#bytesplice
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2023-28120). Fix: Update that package to its patched version.
-
Worth fixing CVE-2026-33169 rails: rails-activesupport: Active Support: Denial of Service via crafted long digit strings
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2026-33169). Fix: Update that package to its patched version.
-
Worth fixing CVE-2026-33170 Rails: Active Support: Active Support: Cross-Site Scripting (XSS) due to improper HTML safety flag propagation in SafeBuffer#%
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2026-33170). Fix: Update that package to its patched version.
-
Worth fixing CVE-2018-1000201 ruby-ffi DDL loading issue on Windows OS
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2018-1000201). Fix: Update that package to its patched version.
-
Worth fixing CVE-2017-1002201 In haml versions prior to version 5.0.0.beta.2, when using user input ...
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2017-1002201). Fix: Update that package to its patched version.
-
Worth fixing CVE-2014-10077 rubygem-i18n: denial of service in Hash#slice in lib/i18n/core_ext/hash.rb
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2014-10077). Fix: Update that package to its patched version.
-
Worth fixing CVE-2020-10663 rubygem-json: Unsafe object creation vulnerability in JSON
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2020-10663). Fix: Update that package to its patched version.
-
Worth fixing CVE-2020-8161 rubygem-rack: directory traversal in Rack::Directory
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2020-8161). Fix: Update that package to its patched version.
-
Worth fixing CVE-2020-8184 rubygem-rack: percent-encoded cookies can be used to overwrite existing prefixed cookie names
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2020-8184). Fix: Update that package to its patched version.
-
Worth fixing CVE-2022-30122 rubygem-rack: crafted multipart POST request may cause a DoS
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2022-30122). Fix: Update that package to its patched version.
-
Worth fixing CVE-2022-44570 rubygem-rack: denial of service in Content-Disposition parsing
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2022-44570). Fix: Update that package to its patched version.
-
Worth fixing CVE-2022-44571 rubygem-rack: denial of service in Content-Disposition parsing
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2022-44571). Fix: Update that package to its patched version.
-
Worth fixing CVE-2022-44572 rubygem-rack: denial of service in Content-Disposition parsing
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2022-44572). Fix: Update that package to its patched version.
-
Worth fixing CVE-2023-27530 rubygem-rack: Denial of service in Multipart MIME parsing
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2023-27530). Fix: Update that package to its patched version.
-
Worth fixing CVE-2024-26141 rubygem-rack: Possible DoS Vulnerability with Range Header in Rack
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2024-26141). Fix: Update that package to its patched version.
-
Worth fixing CVE-2024-26146 rubygem-rack: Possible Denial of Service Vulnerability in Rack Header Parsing
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2024-26146). Fix: Update that package to its patched version.
-
Worth fixing CVE-2025-27111 rack: rubygem-rack: Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2025-27111). Fix: Update that package to its patched version.
-
Worth fixing CVE-2025-27610 rack: rubygem-rack: Local File Inclusion in Rack::Static
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2025-27610). Fix: Update that package to its patched version.
-
Worth fixing CVE-2025-46727 rubygem-rack: Unbounded-Parameter DoS in Rack::QueryParser
apidocs/cloud-api-source/Gemfile.lock
A package you depend on has a known security hole (CVE-2025-46727). Fix: Update that package to its patched version.