field_test
A/B testing for Rails
Activity
- Latest release
- 5mo ago
- Total releases
- 24
- Cadence
- ~4 months
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Dec 14, 2016
| Version | Released | |
|---|---|---|
1.0.0
major
| ||
0.8.0
minor
| ||
0.7.0
minor
| ||
0.6.1
patch
| ||
0.6.0
minor
| ||
0.5.5
patch
| ||
0.5.4
patch
| ||
0.5.3
patch
| ||
0.5.2
patch
| ||
0.5.1
patch
| ||
0.5.0
minor
| ||
0.4.1
patch
|
0.4.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.4.0
minor
|
0.4.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.3.2
patch
1 CVE
CVE-2020-16252
GHSA-w542-cpp9-r3g7
Aug 05, 2020
Field Test CSRF vulnerability
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The Field Test dashboard is vulnerable to cross-site request forgery (CSRF) with non-session based authentication methods in versions v0.2.0 through v0.3.2. ImpactThe Field Test dashboard is vulnerable to CSRF with non-session based authentication methods, like basic authentication. Session-based authentication methods (like Devise's default authentication) are not affected. A CSRF attack works by getting an authorized user to visit a malicious website and then performing requests on behalf of the user. In this instance, a single endpoint is affected, which allows for changing the variant assigned to a user. All users running an affected release should upgrade immediately. Technical DetailsField Test uses the Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.3.0
0.3.1
0.3.2
Fixed in
0.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.3.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.3.1
patch
1 CVE
CVE-2020-16252
GHSA-w542-cpp9-r3g7
Aug 05, 2020
Field Test CSRF vulnerability
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The Field Test dashboard is vulnerable to cross-site request forgery (CSRF) with non-session based authentication methods in versions v0.2.0 through v0.3.2. ImpactThe Field Test dashboard is vulnerable to CSRF with non-session based authentication methods, like basic authentication. Session-based authentication methods (like Devise's default authentication) are not affected. A CSRF attack works by getting an authorized user to visit a malicious website and then performing requests on behalf of the user. In this instance, a single endpoint is affected, which allows for changing the variant assigned to a user. All users running an affected release should upgrade immediately. Technical DetailsField Test uses the Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.3.0
0.3.1
0.3.2
Fixed in
0.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.3.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.3.0
minor
2 CVEs
CVE-2020-16252
GHSA-w542-cpp9-r3g7
Aug 05, 2020
Field Test CSRF vulnerability
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The Field Test dashboard is vulnerable to cross-site request forgery (CSRF) with non-session based authentication methods in versions v0.2.0 through v0.3.2. ImpactThe Field Test dashboard is vulnerable to CSRF with non-session based authentication methods, like basic authentication. Session-based authentication methods (like Devise's default authentication) are not affected. A CSRF attack works by getting an authorized user to visit a malicious website and then performing requests on behalf of the user. In this instance, a single endpoint is affected, which allows for changing the variant assigned to a user. All users running an affected release should upgrade immediately. Technical DetailsField Test uses the Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.3.0
0.3.1
0.3.2
Fixed in
0.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-13146
GHSA-wg9m-gw3h-hg83
Jul 16, 2019
field_test gem contains injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications use it. If an application treats arbitrary variants as trusted, this can lead to a variety of potential vulnerabilities like SQL injection or cross-site scripting (XSS). Affected versions
0.3.0
Fixed in
0.3.1
References
Updated Mar 03, 2025 · Source: OSV.dev |
0.3.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.2.4
patch
1 CVE
CVE-2020-16252
GHSA-w542-cpp9-r3g7
Aug 05, 2020
Field Test CSRF vulnerability
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The Field Test dashboard is vulnerable to cross-site request forgery (CSRF) with non-session based authentication methods in versions v0.2.0 through v0.3.2. ImpactThe Field Test dashboard is vulnerable to CSRF with non-session based authentication methods, like basic authentication. Session-based authentication methods (like Devise's default authentication) are not affected. A CSRF attack works by getting an authorized user to visit a malicious website and then performing requests on behalf of the user. In this instance, a single endpoint is affected, which allows for changing the variant assigned to a user. All users running an affected release should upgrade immediately. Technical DetailsField Test uses the Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.3.0
0.3.1
0.3.2
Fixed in
0.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.2.3
patch
1 CVE
CVE-2020-16252
GHSA-w542-cpp9-r3g7
Aug 05, 2020
Field Test CSRF vulnerability
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The Field Test dashboard is vulnerable to cross-site request forgery (CSRF) with non-session based authentication methods in versions v0.2.0 through v0.3.2. ImpactThe Field Test dashboard is vulnerable to CSRF with non-session based authentication methods, like basic authentication. Session-based authentication methods (like Devise's default authentication) are not affected. A CSRF attack works by getting an authorized user to visit a malicious website and then performing requests on behalf of the user. In this instance, a single endpoint is affected, which allows for changing the variant assigned to a user. All users running an affected release should upgrade immediately. Technical DetailsField Test uses the Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.3.0
0.3.1
0.3.2
Fixed in
0.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.2.2
patch
1 CVE
CVE-2020-16252
GHSA-w542-cpp9-r3g7
Aug 05, 2020
Field Test CSRF vulnerability
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The Field Test dashboard is vulnerable to cross-site request forgery (CSRF) with non-session based authentication methods in versions v0.2.0 through v0.3.2. ImpactThe Field Test dashboard is vulnerable to CSRF with non-session based authentication methods, like basic authentication. Session-based authentication methods (like Devise's default authentication) are not affected. A CSRF attack works by getting an authorized user to visit a malicious website and then performing requests on behalf of the user. In this instance, a single endpoint is affected, which allows for changing the variant assigned to a user. All users running an affected release should upgrade immediately. Technical DetailsField Test uses the Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.3.0
0.3.1
0.3.2
Fixed in
0.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.2.1
patch
1 CVE
CVE-2020-16252
GHSA-w542-cpp9-r3g7
Aug 05, 2020
Field Test CSRF vulnerability
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The Field Test dashboard is vulnerable to cross-site request forgery (CSRF) with non-session based authentication methods in versions v0.2.0 through v0.3.2. ImpactThe Field Test dashboard is vulnerable to CSRF with non-session based authentication methods, like basic authentication. Session-based authentication methods (like Devise's default authentication) are not affected. A CSRF attack works by getting an authorized user to visit a malicious website and then performing requests on behalf of the user. In this instance, a single endpoint is affected, which allows for changing the variant assigned to a user. All users running an affected release should upgrade immediately. Technical DetailsField Test uses the Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.3.0
0.3.1
0.3.2
Fixed in
0.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2020-16252
GHSA-w542-cpp9-r3g7
Aug 05, 2020
Field Test CSRF vulnerability
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The Field Test dashboard is vulnerable to cross-site request forgery (CSRF) with non-session based authentication methods in versions v0.2.0 through v0.3.2. ImpactThe Field Test dashboard is vulnerable to CSRF with non-session based authentication methods, like basic authentication. Session-based authentication methods (like Devise's default authentication) are not affected. A CSRF attack works by getting an authorized user to visit a malicious website and then performing requests on behalf of the user. In this instance, a single endpoint is affected, which allows for changing the variant assigned to a user. All users running an affected release should upgrade immediately. Technical DetailsField Test uses the Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.3.0
0.3.1
0.3.2
Fixed in
0.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.1.2
patch
| ||
0.1.1
patch
| ||
0.1.0
initial
|