Vendor
critical
advisory
Ruby and Ruby on Rails Vulnerability Allows Code Execution
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Ruby and Ruby on Rails to bypass security measures and execute arbitrary code.
Ruby +1
code-execution
rails
2r
1t
high
advisory
Rails Active Storage Vulnerability Allows Arbitrary File Deletion
2 rules 1 TTPA vulnerability in Rails Active Storage allows attackers to delete arbitrary files in the storage directory by exploiting glob metacharacters in blob keys passed to `Dir.glob`.
Active Storage
rails
active_storage
file_deletion
vulnerability
2r
1t
medium
advisory
Katalyst Koi Session Cookies Replayable After Logout
2 rules 1 TTPKatalyst Koi versions before 4.20.0 and between 5.0.0 and 5.6.0 fail to invalidate admin session cookies upon logout, allowing attackers with a valid cookie to maintain unauthorized access.
katalyst-koi +2
session-replay
vulnerability
authentication
2r
1t