Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 22 additions & 5 deletions gems/datagrid/CVE-2019-14281.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,13 +2,30 @@
gem: datagrid
cve: 2019-14281
ghsa: rqp5-pg7w-832p
url: https://github.com/rubygems/rubygems.org/issues/2072
url: https://nvd.nist.gov/vuln/detail/CVE-2019-14281
date: 2019-07-31
title: Code execution backdoor in datagrid
description: |
The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included
a code-execution backdoor inserted by a third party.
The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org,
included a code-execution backdoor inserted by a third party.
cvss_v2: 7.5
cvss_v3: 9.8
unaffected_versions:
- "< 1.0.6"
- "> 1.0.6"
cvss_v3: 9.8
- "> 1.0.6, < 1.5.10"
patched_versions:
- "> 1.5.10"
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2019-14281
- https://rubygems.org/gems/datagrid/versions/1.6.0
- https://rubygems.org/gems/datagrid/versions
- https://github.com/rubygems/rubygems.org/issues/2072
- https://github.com/advisories/GHSA-rqp5-pg7w-832p
notes: |
- cvss_v2 and cvss_v3 (also GHSA URL) from nvd.nist.gov URL.
- https://rubygems.org/gems/datagrid/versions/1.5.10 was yanked.
- https://rubygems.org/gems/datagrid/versions/1.0.6 was yanked.
- https://github.com/rubygems/rubygems.org/issues/2072 (please yank 1.0.6)
- https://rubygems.org/gems/data_grid has only 0.0.1 and 0.0.2 release.
- https://github.com/kkempin/data_grid has only 0.0.1.
19 changes: 18 additions & 1 deletion gems/fog-dragonfly/CVE-2013-5671.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,24 @@ description: |
failing to properly sanitize input passed via the imagemagickutils.rb script.
This may allow a remote attacker to execute arbitrary commands.

This gem has been renamed. Please use "dragonfly" from now on.
lib/dragonfly/imagemagickutils.rb in the fog-dragonfly gem 0.8.2
for Ruby allows remote attackers to execute arbitrary commands
via unspecified vectors.

NOTE: This gem has been renamed. Please use "dragonfly" 1.0.0 from now on.
cvss_v2: 7.5
patched_versions:
- ">= 0.8.4"
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2013-5671
- https://rubygems.org/gems/dragonfly/versions/1.0
- http://seclists.org/fulldisclosure/2013/Sep/18
- http://seclists.org/oss-sec/2013/q3/526
- http://seclists.org/oss-sec/2013/q3/528
- http://www.vapid.dhs.org/advisories/fog-dragonfly-0.8.2-cmd-inj.html
- https://github.com/advisories/GHSA-qrgf-jqqm-x7xv
notes: |
- cvss_v2 from nvd.nist.gov URL.
- https://rubygems.org/gems/fog-dragonfly has only 0.8.1 and 0.8.2
releases. Now use (renamed) "dragonfly" from now on.
10 changes: 7 additions & 3 deletions gems/iodine/CVE-2026-41146.yml
Original file line number Diff line number Diff line change
Expand Up @@ -258,14 +258,18 @@ description: |
- The gem vendors a copy of the vulnerable parser in
`ext/iodine/fio_json_parser.h`
cvss_v4: 8.7
patched_versions:
- ">= 0.7.59"
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2026-41146
- https://github.com/boazsegev/iodine/releases/tag/v0.7.58
- https://rubygems.org/gems/iodine/versions/0.7.59
- https://github.com/boazsegev/iodine/releases/tag/v0.7.59
- https://github.com/boazsegev/iodine/compare/v0.7.58...v0.7.59
- https://github.com/boazsegev/iodine/commit/0855989d74098d838b972520835cfc256bc479bc
- https://github.com/boazsegev/facil.io/commit/5128747363055201d3ecf0e29bf0a961703c9fa0
- https://github.com/boazsegev/facil.io/security/advisories/GHSA-2x79-gwq3-vxxm
- https://github.com/advisories/GHSA-2x79-gwq3-vxxm
notes: |
- FYI: iodine commit above contains the unreleased patch.
- Found GHSA's `patched_versions:` field is "0.7.59" but never released.
- cvss_v4 from nvd.nist.gov URL.
- FYI: iodine commit above in 0.7.59 release.
12 changes: 10 additions & 2 deletions gems/openc3-cosmos-tool-iframe/CVE-2025-28382.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
gem: openc3-cosmos-tool-iframe
cve: 2025-28382
ghsa: cf8v-5mrc-jv7f
url: https://github.com/advisories/GHSA-cf8v-5mrc-jv7f
url: https://nvd.nist.gov/vuln/detail/CVE-2025-28382
title: OpenC3 COSMOS Vulnerable to Directory Traversal via
openc3-api/tables endpoint
date: 2025-06-13
Expand All @@ -12,10 +12,18 @@ description: |
cvss_v3: 7.5
unaffected_versions:
- "< 6.0.0"
notes: Never patched
patched_versions:
- ">= 6.1.0"
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2025-28382
- https://rubygems.org/gems/openc3-cosmos-tool-iframe/versions/6.1.0
- https://github.com/OpenC3/cosmos/releases/tag/v6.1.0
- https://github.com/OpenC3/cosmos/pull/1828/changes/fc7e11310a7cdf9f1939886e1b29009db4d4b718
- https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework
- https://openc3.com
- https://github.com/advisories/GHSA-cf8v-5mrc-jv7f
notes: |
- cvss_v3 from GHSA URL.
- NOTE: gem name is "openc3-cosmos-tool-iframe" and repo name is "cosmos".
- /tag/ URL has reference to CVE-2025-28382.
12 changes: 10 additions & 2 deletions gems/openc3-cosmos-tool-iframe/CVE-2025-28384.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
gem: openc3-cosmos-tool-iframe
cve: 2025-28384
ghsa: p67j-387g-75wc
url: https://github.com/advisories/GHSA-p67j-387g-75wc
url: https://nvd.nist.gov/vuln/detail/CVE-2025-28384
title: OpenC3 COSMOS Vulnerable to Directory Traversal via
/script-api/scripts/ endpoint
date: 2025-06-13
Expand All @@ -12,10 +12,18 @@ description: |
cvss_v3: 9.1
unaffected_versions:
- "< 6.0.0"
notes: Never patched
patched_versions:
- ">= 6.1.0"
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2025-28384
- https://rubygems.org/gems/openc3-cosmos-tool-iframe/versions/6.1.0
- https://github.com/OpenC3/cosmos/releases/tag/v6.1.0
- https://github.com/OpenC3/cosmos/pull/1828/changes/fc7e11310a7cdf9f1939886e1b29009db4d4b718
- https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework
- https://openc3.com
- https://github.com/advisories/GHSA-p67j-387g-75wc
notes: |
- cvss_v3 from GHSA URL.
- NOTE: gem name is "openc3-cosmos-tool-iframe" and repo name is "cosmos".
- /tag/ URL has reference to CVE-2025-28384.
30 changes: 23 additions & 7 deletions gems/oxidized-web/CVE-2019-25088.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,18 +2,34 @@
gem: oxidized-web
cve: 2019-25088
ghsa: 8qwh-rm6c-jv96
url: https://github.com/ytti/oxidized-web/pull/195
url: https://nvd.nist.gov/vuln/detail/CVE-2019-25088
title: Oxidized Web vulnerable to Cross-site Scripting
date: 2022-12-27
description: |
A vulnerability was found in ytti Oxidized Web. It has been classified
as problematic. Affected is an unknown function of the file `lib/oxidized/web/views/conf_search.haml`.
The manipulation of the argument `to_research` leads to cross site scripting. It
is possible to launch the attack remotely. The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45.
It is recommended to apply a patch to fix this issue. VDB-216870 is the identifier
assigned to this vulnerability.
as problematic. Affected is an unknown function of the file
`lib/oxidized/web/views/conf_search.haml`.

The manipulation of the argument `to_research` leads to cross site
scripting. It is possible to launch the attack remotely.
The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45.

It is recommended to apply a patch to fix this issue.
VDB-216870 is the identifier assigned to this vulnerability.
cvss_v3: 5.4
patched_versions:
- ">= 0.14.0"
related:
url:
- https://github.com/ytti/oxidized-web/commit/55ab9bdc68b03ebce9280b8746ef31d7fdedcc45
- https://nvd.nist.gov/vuln/detail/CVE-2019-25088
- https://rubygems.org/gems/oxidized-web/versions/0.14.0
- https://github.com/ytti/oxidized-web/releases#release-0.14.0
- https://github.com/ytti/oxidized-web/compare/0.13.1...0.14.0
- https://github.com/ytti/oxidized-web/pull/195
- https://github.com/ytti/oxidized-web/pull/195/changes/12c07e69168bb5b4dfd4dbfed857491ed095dfd0
- https://vuldb.com/?id.216870
- https://github.com/advisories/GHSA-8qwh-rm6c-jv96
notes: |
- cvss_v3 from GHSA URL.
- PR#195: [escape user input to fix XSS "vulnerability"]
- See /changes/ UR (fix)L in /compare/ URL.
12 changes: 7 additions & 5 deletions gems/pay/GHSA-mjgf-xj26-9qf9.yml
Original file line number Diff line number Diff line change
Expand Up @@ -43,11 +43,13 @@ patched_versions:
related:
url:
- https://advisories.gitlab.com/gem/pay/GHSA-mjgf-xj26-9qf9
- https://rubygems.org/gems/pay/versions/11.6.2
- https://github.com/pay-rails/pay/releases/tag/v11.6.2
- https://github.com/pay-rails/pay/commit/ba6494109d88209fba2a4df2d9d6373fe81ed805
- https://github.com/pay-rails/pay/issues/1232
- https://github.com/rubysec/ruby-advisory-db/pull/1158
- https://github.com/pay-rails/pay/security/advisories/GHSA-mjgf-xj26-9qf9
- https://github.com/advisories/GHSA-mjgf-xj26-9qf9
notes: |
- Fixed in 11.6.2.
- https://github.com/pay-rails/pay/releases/tag/v11.6.2
- https://rubygems.org/gems/pay/versions/11.6.2
- cvss_v3 value comes from project advisory.
- No cve value, so missing cvss_v2 and cvss_v4 values.
- cvss_v3 from GHSA URL.
- No cve in GHSA URL.
10 changes: 9 additions & 1 deletion gems/spina/CVE-2024-7106.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,12 +24,20 @@ description: |
cvss_v2: 5.0
cvss_v3: 4.3
cvss_v4: 6.9
notes: Never patched
patched_versions:
- ">= 2.21.0"
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2024-7106
- https://github.com/SpinaCMS/Spina/compare/v2.21.0...main
- https://github.com/SpinaCMS/Spina/commit/ccc3f5d2f76423561d17acf522baddb5c3fa8d43
- https://github.com/SpinaCMS/Spina/pull/1441/changes/a22b1d6530d8166e0de7117ce3885100b2dbe461
- https://github.com/SpinaCMS/Spina/pull/1441
- https://github.com/SpinaCMS/Spina/issues/1381
- https://github.com/topsky979/Security-Collections/blob/main/cve3/README.md
- https://vuldb.com/?ctiid.272431
- https://vuldb.com/?id.272431
- https://vuldb.com/?submit.376769
- https://github.com/advisories/GHSA-wqw3-p83g-r24v
notes: |
- See CVE reference in /compare/v2.21.0 URL.
Loading