geokit-rails
Official Geokit plugin for Rails/ActiveRecord. Provides location-based goodness for your Rails app. Requires the Geokit gem.
Activity
- Latest release
- 3y ago
- Total releases
- 10
- Cadence
- ~1.3 years
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Sep 07, 2010
| Version | Released | |
|---|---|---|
2.5.0
minor
|
2.5.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.3.2
patch
1 CVE
CVE-2023-26153
GHSA-7xvc-v44j-46fh
Oct 06, 2023
geokit-rails Command Injection vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. Note: An attacker can use this vulnerability to execute commands on the host system. Affected versions
1.1.4
2.0.0
2.0.0.rc1
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
Fixed in
2.5.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.3.2
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.3.1
patch
1 CVE
CVE-2023-26153
GHSA-7xvc-v44j-46fh
Oct 06, 2023
geokit-rails Command Injection vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. Note: An attacker can use this vulnerability to execute commands on the host system. Affected versions
1.1.4
2.0.0
2.0.0.rc1
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
Fixed in
2.5.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.3.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.3.0
minor
1 CVE
CVE-2023-26153
GHSA-7xvc-v44j-46fh
Oct 06, 2023
geokit-rails Command Injection vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. Note: An attacker can use this vulnerability to execute commands on the host system. Affected versions
1.1.4
2.0.0
2.0.0.rc1
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
Fixed in
2.5.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.3.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.2.0
minor
1 CVE
CVE-2023-26153
GHSA-7xvc-v44j-46fh
Oct 06, 2023
geokit-rails Command Injection vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. Note: An attacker can use this vulnerability to execute commands on the host system. Affected versions
1.1.4
2.0.0
2.0.0.rc1
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
Fixed in
2.5.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.2.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.1.0
minor
1 CVE
CVE-2023-26153
GHSA-7xvc-v44j-46fh
Oct 06, 2023
geokit-rails Command Injection vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. Note: An attacker can use this vulnerability to execute commands on the host system. Affected versions
1.1.4
2.0.0
2.0.0.rc1
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
Fixed in
2.5.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.1.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.0.1
patch
1 CVE
CVE-2023-26153
GHSA-7xvc-v44j-46fh
Oct 06, 2023
geokit-rails Command Injection vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. Note: An attacker can use this vulnerability to execute commands on the host system. Affected versions
1.1.4
2.0.0
2.0.0.rc1
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
Fixed in
2.5.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2023-26153
GHSA-7xvc-v44j-46fh
Oct 06, 2023
geokit-rails Command Injection vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. Note: An attacker can use this vulnerability to execute commands on the host system. Affected versions
1.1.4
2.0.0
2.0.0.rc1
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
Fixed in
2.5.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.0.rc1
pre
1 CVE
CVE-2023-26153
GHSA-7xvc-v44j-46fh
Oct 06, 2023
geokit-rails Command Injection vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. Note: An attacker can use this vulnerability to execute commands on the host system. Affected versions
1.1.4
2.0.0
2.0.0.rc1
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
Fixed in
2.5.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.4
initial
1 CVE
CVE-2023-26153
GHSA-7xvc-v44j-46fh
Oct 06, 2023
geokit-rails Command Injection vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. Note: An attacker can use this vulnerability to execute commands on the host system. Affected versions
1.1.4
2.0.0
2.0.0.rc1
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
Fixed in
2.5.0
References
Updated Feb 16, 2024 · Source: OSV.dev |