FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

[Snyk] Fix for 20 vulnerabilities by one3chens · Pull Request #10 · feicc/travis-api · GitHub

[Snyk] Fix for 20 vulnerabilities - #10

Open
one3chens wants to merge 1 commit into
masterfrom
snyk-fix-2f938c446670d5dd487249e9a6b1cb0a
Open

one3chens wants to merge 1 commit into
masterfrom
snyk-fix-2f938c446670d5dd487249e9a6b1cb0a

Conversation

Copy link
Copy Markdown
Member

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `rubygems` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • Gemfile
⚠️ Warning
Failed to update the Gemfile.lock, please update manually before merging.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
834/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-RUBY-ACTIVESUPPORT-569598
No Mature
589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-RUBY-ADDRESSABLE-1316242
No No Known Exploit
604/1000
Why? Has a fix available, CVSS 7.8
DLL Loading Issue
SNYK-RUBY-FFI-22037
No No Known Exploit
679/1000
Why? Has a fix available, CVSS 9.3
Denial of Service (DoS)
SNYK-RUBY-JSON-560838
No No Known Exploit
694/1000
Why? Has a fix available, CVSS 9.6
Incorrect Permissions
SNYK-RUBY-NETADDR-472456
No No Known Exploit
704/1000
Why? Has a fix available, CVSS 9.8
Arbitrary Code Injection
SNYK-RUBY-RACK-2848599
Yes No Known Exploit
589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-RUBY-RACK-2848600
Yes No Known Exploit
479/1000
Why? Has a fix available, CVSS 5.3
Information Exposure
SNYK-RUBY-RACK-538324
No No Known Exploit
589/1000
Why? Has a fix available, CVSS 7.5
Directory Traversal
SNYK-RUBY-RACK-569066
Yes No Known Exploit
646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Cross-site Request Forgery (CSRF)
SNYK-RUBY-RACK-572377
Yes Proof of Concept
519/1000
Why? Has a fix available, CVSS 6.1
Cross-site Scripting (XSS)
SNYK-RUBY-RACK-72567
No No Known Exploit
399/1000
Why? Has a fix available, CVSS 3.7
Side-channel attack
SNYK-RUBY-RACKPROTECTION-20394
Yes No Known Exploit
509/1000
Why? Has a fix available, CVSS 5.9
Timing Attack
SNYK-RUBY-RACKPROTECTION-20395
No No Known Exploit
479/1000
Why? Has a fix available, CVSS 5.3
Directory Traversal
SNYK-RUBY-RACKPROTECTION-22019
No No Known Exploit
686/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
Arbitrary Code Injection
SNYK-RUBY-RAKE-552000
Yes Proof of Concept
509/1000
Why? Has a fix available, CVSS 5.9
Timing Attack
SNYK-RUBY-SINATRA-20488
Yes No Known Exploit
519/1000
Why? Has a fix available, CVSS 6.1
Cross-site Scripting (XSS)
SNYK-RUBY-SINATRA-22027
Yes No Known Exploit
589/1000
Why? Has a fix available, CVSS 7.5
Improper Input Validation
SNYK-RUBY-SINATRA-2806372
Yes No Known Exploit
589/1000
Why? Has a fix available, CVSS 7.5
Directory Traversal
SNYK-RUBY-YARD-22004
No No Known Exploit
624/1000
Why? Has a fix available, CVSS 8.2
Directory Traversal
SNYK-RUBY-YARD-455636
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Directory Traversal
🦉 Directory Traversal
🦉 Cross-site Scripting (XSS)
🦉 More lessons are available in Snyk Learn

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL