kaminari
Kaminari is a Scope & Engine based, clean, powerful, agnostic, customizable and sophisticated paginator for Rails 4+
Activity
- Latest release
- 4y ago
- Total releases
- 53
- Cadence
- ~2 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Feb 05, 2011
| Version | Released | |
|---|---|---|
1.2.2
patch
|
1.2.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.2.1
patch
|
1.2.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.2.0
minor
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.2.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.1.1
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.1.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.1.0
minor
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.1.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.0.1
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.0.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.0.0
major
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.0.0
major
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.0.0.beta2
pre
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.0.0.beta2
pre
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.0.0.rc1
pre
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.0.0.rc1
pre
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.17.0
minor
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.17.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.16.3
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.16.3
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.16.2
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.16.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.16.1
patch
2 CVEs
CVE-2024-32978
GHSA-7r3j-qmr4-jfpj
May 28, 2024
Kaminari Insecure File Permissions Vulnerability
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
A moderate severity security vulnerability has been identified in the Kaminari pagination library for Ruby on Rails, concerning insecure file permissions. This advisory outlines the vulnerability, affected versions, and provides guidance for mitigation. ImpactThis vulnerability is of moderate severity due to the potential for unauthorized write access to particular Ruby files managed by the library. Such access could lead to the alteration of application behavior or data integrity issues. ResolutionThose who use the Those who manually download and decompressing the affected versions are advised to update to 0.16.2 or later version of Kaminari where file permissions have been adjusted to enhance security. WorkaroundsIf upgrading is not feasible immediately, manually adjusting the file permissions on the server to All Affected Versions:
In addition to the previously mentioned files, security tools like AWS Inspector might also identify other files as unsafe. These files, although not loaded or used at runtime, may still be flagged. To avoid any potential confusion in your logs and ensure system integrity, we recommend updating the permissions for these files as well. This proactive measure helps maintain a clean security posture and minimizes unnecessary alerts. Version 0.15.0 and 0.15.1:
Version 0.16.0:
Version 0.16.1:
ReferencesOfficial Kaminari repository link (this page) AcknowledgementsWe thank Gareth Jones for discovering and reporting this issue. Their diligent work is instrumental in our ongoing efforts to maintain and improve software security. Affected versions
0.15.0
0.15.1
0.16.0
0.16.1
Fixed in
0.16.2
References Updated May 31, 2024 · Source: OSV.dev
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.16.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.16.0
minor
2 CVEs
CVE-2024-32978
GHSA-7r3j-qmr4-jfpj
May 28, 2024
Kaminari Insecure File Permissions Vulnerability
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
A moderate severity security vulnerability has been identified in the Kaminari pagination library for Ruby on Rails, concerning insecure file permissions. This advisory outlines the vulnerability, affected versions, and provides guidance for mitigation. ImpactThis vulnerability is of moderate severity due to the potential for unauthorized write access to particular Ruby files managed by the library. Such access could lead to the alteration of application behavior or data integrity issues. ResolutionThose who use the Those who manually download and decompressing the affected versions are advised to update to 0.16.2 or later version of Kaminari where file permissions have been adjusted to enhance security. WorkaroundsIf upgrading is not feasible immediately, manually adjusting the file permissions on the server to All Affected Versions:
In addition to the previously mentioned files, security tools like AWS Inspector might also identify other files as unsafe. These files, although not loaded or used at runtime, may still be flagged. To avoid any potential confusion in your logs and ensure system integrity, we recommend updating the permissions for these files as well. This proactive measure helps maintain a clean security posture and minimizes unnecessary alerts. Version 0.15.0 and 0.15.1:
Version 0.16.0:
Version 0.16.1:
ReferencesOfficial Kaminari repository link (this page) AcknowledgementsWe thank Gareth Jones for discovering and reporting this issue. Their diligent work is instrumental in our ongoing efforts to maintain and improve software security. Affected versions
0.15.0
0.15.1
0.16.0
0.16.1
Fixed in
0.16.2
References Updated May 31, 2024 · Source: OSV.dev
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.16.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.15.1
patch
2 CVEs
CVE-2024-32978
GHSA-7r3j-qmr4-jfpj
May 28, 2024
Kaminari Insecure File Permissions Vulnerability
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
A moderate severity security vulnerability has been identified in the Kaminari pagination library for Ruby on Rails, concerning insecure file permissions. This advisory outlines the vulnerability, affected versions, and provides guidance for mitigation. ImpactThis vulnerability is of moderate severity due to the potential for unauthorized write access to particular Ruby files managed by the library. Such access could lead to the alteration of application behavior or data integrity issues. ResolutionThose who use the Those who manually download and decompressing the affected versions are advised to update to 0.16.2 or later version of Kaminari where file permissions have been adjusted to enhance security. WorkaroundsIf upgrading is not feasible immediately, manually adjusting the file permissions on the server to All Affected Versions:
In addition to the previously mentioned files, security tools like AWS Inspector might also identify other files as unsafe. These files, although not loaded or used at runtime, may still be flagged. To avoid any potential confusion in your logs and ensure system integrity, we recommend updating the permissions for these files as well. This proactive measure helps maintain a clean security posture and minimizes unnecessary alerts. Version 0.15.0 and 0.15.1:
Version 0.16.0:
Version 0.16.1:
ReferencesOfficial Kaminari repository link (this page) AcknowledgementsWe thank Gareth Jones for discovering and reporting this issue. Their diligent work is instrumental in our ongoing efforts to maintain and improve software security. Affected versions
0.15.0
0.15.1
0.16.0
0.16.1
Fixed in
0.16.2
References Updated May 31, 2024 · Source: OSV.dev
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.15.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.15.0
minor
2 CVEs
CVE-2024-32978
GHSA-7r3j-qmr4-jfpj
May 28, 2024
Kaminari Insecure File Permissions Vulnerability
6.6
/ 10
Medium
Network
High
High
None
Unchanged
High
High
High
A moderate severity security vulnerability has been identified in the Kaminari pagination library for Ruby on Rails, concerning insecure file permissions. This advisory outlines the vulnerability, affected versions, and provides guidance for mitigation. ImpactThis vulnerability is of moderate severity due to the potential for unauthorized write access to particular Ruby files managed by the library. Such access could lead to the alteration of application behavior or data integrity issues. ResolutionThose who use the Those who manually download and decompressing the affected versions are advised to update to 0.16.2 or later version of Kaminari where file permissions have been adjusted to enhance security. WorkaroundsIf upgrading is not feasible immediately, manually adjusting the file permissions on the server to All Affected Versions:
In addition to the previously mentioned files, security tools like AWS Inspector might also identify other files as unsafe. These files, although not loaded or used at runtime, may still be flagged. To avoid any potential confusion in your logs and ensure system integrity, we recommend updating the permissions for these files as well. This proactive measure helps maintain a clean security posture and minimizes unnecessary alerts. Version 0.15.0 and 0.15.1:
Version 0.16.0:
Version 0.16.1:
ReferencesOfficial Kaminari repository link (this page) AcknowledgementsWe thank Gareth Jones for discovering and reporting this issue. Their diligent work is instrumental in our ongoing efforts to maintain and improve software security. Affected versions
0.15.0
0.15.1
0.16.0
0.16.1
Fixed in
0.16.2
References Updated May 31, 2024 · Source: OSV.dev
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.15.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.14.1
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.14.0
minor
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.13.0
minor
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.13.0
minor
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.12.4
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.12.2
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.12.3
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.12.1
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.12.0
minor
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.11.0
minor
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.4
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.3
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.2
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.0
minor
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.1
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.13
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.12
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.10
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.8
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.7
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.9
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.6
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.3
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.4
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.5
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.2
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.0
minor
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.1
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.8.0
minor
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.1
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.0
minor
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.1
patch
1 CVE
CVE-2020-11082
GHSA-r5jw-62xg-j433
May 28, 2020
Cross-Site Scripting in Kaminari
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
ImpactIn Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1. ReleasesThe 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability. WorkaroundsApplication developers who can't update the gem can workaround by overriding the
CreditsThanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability. Affected versions
0.1.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
+ 39 more Show less
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.10
0.9.12
0.9.13
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.0.0
1.0.0.beta2
1.0.0.rc1
1.0.1
1.1.0
1.1.1
1.2.0
Fixed in
1.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |