rubygems actionpack Vulnerabilities
CVE security advisories and vulnerability history for actionpack by rubygems.
Last updated
CVE security advisories and vulnerability history for actionpack by rubygems.
Last updated
rubygems actionpack has 63 published CVE records since 2009, of which 2 are in CISA's Known Exploited Vulnerabilities catalog and 9 have a known public exploit. The average CVSS base score across scored CVEs is 5.7.
This page aggregates every publicly disclosed vulnerability (CVE) affecting rubygems actionpack, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
How the CVSS severity of rubygems actionpack's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
48 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
2
2 of rubygems actionpack's CVEs are confirmed exploited in the wild.
Public exploits
9
9 of rubygems actionpack's CVEs have a known public exploit available.
Browse every rubygems actionpack version named in a CVE, then pick one to see only the CVEs that affect it.
63 CVEs
Added to CISA KEV 2022-03-25
Showing 30 of 63
The CWE weakness categories most often found in rubygems actionpack CVEs. Follow any weakness for its full explanation.
How many rubygems actionpack CVEs were published each year.
Browse vulnerabilities for other products by rubygems.
Common questions about rubygems actionpack vulnerabilities.
rubygems actionpack has 63 published CVE records since 2009.
Yes — 2 of rubygems actionpack's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Yes — 9 of rubygems actionpack's CVEs have a known public exploit.
100 distinct rubygems actionpack versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
rubygems actionpack's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-601 (URL Redirection to Untrusted Site ('Open Redirect')), CWE-400 (Uncontrolled Resource Consumption), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
The average CVSS base score across rubygems actionpack's scored CVEs is 5.7.
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Monitor new rubygems actionpack vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.