rails_admin
RailsAdmin is a Rails engine that provides an easy-to-use interface for managing your data.
Activity
- Latest release
- 1y ago
- Total releases
- 73
- Cadence
- ~2 months
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Apr 16, 2012
| Version | Released | |
|---|---|---|
3.3.0
minor
|
3.3.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
3.2.1
patch
|
3.2.1
patch
Dependencies (7)
Changelog
Compare changes
|
|
3.2.0
minor
|
3.2.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
3.2.0.rc
pre
|
3.2.0.rc
pre
Dependencies (7)
Changelog
Compare changes
|
|
3.2.0.beta
pre
|
3.2.0.beta
pre
Dependencies (7)
Changelog
Compare changes
|
|
2.3.1
patch
|
2.3.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
3.1.4
patch
|
3.1.4
patch
Dependencies (6)
Changelog
Compare changes
|
|
2.3.0
minor
|
2.3.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
3.1.3
patch
|
3.1.3
patch
Dependencies (6)
Changelog
Compare changes
|
|
3.1.2
patch
1 CVE
CVE-2024-39308
GHSA-8qgm-g2vv-vwvc
Jul 08, 2024
RailsAdmin Cross-site Scripting vulnerability in the list view
Medium
Network
Low
Low
ImpactRailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. The issue was originally reported in https://github.com/railsadminteam/rails_admin/issues/3686. PatchesUpgrade to 3.1.4. The vulnerability itself was patched in 3.1.3 but it has a functionality issue. Initially the vulnerability was thought to exist in versions before 3.0, but it didn't. 2.x users can stay on 2.2.1. Workarounds
Note: The view file created by this needs to be removed after upgrading RailsAdmin afterwards, unless this old view continue to be used. Only do this if you can't upgrade RailsAdmin now for a reason. Referenceshttps://owasp.org/www-community/attacks/xss/ https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-strip_tags Affected versions
3.0.0
3.0.0.beta
3.0.0.beta2
3.0.0.rc
3.0.0.rc2
3.0.0.rc3
3.0.0.rc4
3.1.0
3.1.0.beta
3.1.0.rc
3.1.0.rc2
3.1.1
+ 1 more Show less
3.1.2
Fixed in
3.1.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.1.2
patch
Dependencies (6)
Changelog
Compare changes
|
|
3.1.1
patch
1 CVE
CVE-2024-39308
GHSA-8qgm-g2vv-vwvc
Jul 08, 2024
RailsAdmin Cross-site Scripting vulnerability in the list view
Medium
Network
Low
Low
ImpactRailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. The issue was originally reported in https://github.com/railsadminteam/rails_admin/issues/3686. PatchesUpgrade to 3.1.4. The vulnerability itself was patched in 3.1.3 but it has a functionality issue. Initially the vulnerability was thought to exist in versions before 3.0, but it didn't. 2.x users can stay on 2.2.1. Workarounds
Note: The view file created by this needs to be removed after upgrading RailsAdmin afterwards, unless this old view continue to be used. Only do this if you can't upgrade RailsAdmin now for a reason. Referenceshttps://owasp.org/www-community/attacks/xss/ https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-strip_tags Affected versions
3.0.0
3.0.0.beta
3.0.0.beta2
3.0.0.rc
3.0.0.rc2
3.0.0.rc3
3.0.0.rc4
3.1.0
3.1.0.beta
3.1.0.rc
3.1.0.rc2
3.1.1
+ 1 more Show less
3.1.2
Fixed in
3.1.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.1.1
patch
Dependencies (6)
Changelog
Compare changes
|
|
3.1.0
minor
1 CVE
CVE-2024-39308
GHSA-8qgm-g2vv-vwvc
Jul 08, 2024
RailsAdmin Cross-site Scripting vulnerability in the list view
Medium
Network
Low
Low
ImpactRailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. The issue was originally reported in https://github.com/railsadminteam/rails_admin/issues/3686. PatchesUpgrade to 3.1.4. The vulnerability itself was patched in 3.1.3 but it has a functionality issue. Initially the vulnerability was thought to exist in versions before 3.0, but it didn't. 2.x users can stay on 2.2.1. Workarounds
Note: The view file created by this needs to be removed after upgrading RailsAdmin afterwards, unless this old view continue to be used. Only do this if you can't upgrade RailsAdmin now for a reason. Referenceshttps://owasp.org/www-community/attacks/xss/ https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-strip_tags Affected versions
3.0.0
3.0.0.beta
3.0.0.beta2
3.0.0.rc
3.0.0.rc2
3.0.0.rc3
3.0.0.rc4
3.1.0
3.1.0.beta
3.1.0.rc
3.1.0.rc2
3.1.1
+ 1 more Show less
3.1.2
Fixed in
3.1.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.1.0
minor
Dependencies (6)
Changelog
Compare changes
|
|
3.1.0.rc2
pre
1 CVE
CVE-2024-39308
GHSA-8qgm-g2vv-vwvc
Jul 08, 2024
RailsAdmin Cross-site Scripting vulnerability in the list view
Medium
Network
Low
Low
ImpactRailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. The issue was originally reported in https://github.com/railsadminteam/rails_admin/issues/3686. PatchesUpgrade to 3.1.4. The vulnerability itself was patched in 3.1.3 but it has a functionality issue. Initially the vulnerability was thought to exist in versions before 3.0, but it didn't. 2.x users can stay on 2.2.1. Workarounds
Note: The view file created by this needs to be removed after upgrading RailsAdmin afterwards, unless this old view continue to be used. Only do this if you can't upgrade RailsAdmin now for a reason. Referenceshttps://owasp.org/www-community/attacks/xss/ https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-strip_tags Affected versions
3.0.0
3.0.0.beta
3.0.0.beta2
3.0.0.rc
3.0.0.rc2
3.0.0.rc3
3.0.0.rc4
3.1.0
3.1.0.beta
3.1.0.rc
3.1.0.rc2
3.1.1
+ 1 more Show less
3.1.2
Fixed in
3.1.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.1.0.rc2
pre
Dependencies (6)
Changelog
Compare changes
|
|
3.1.0.rc
pre
1 CVE
CVE-2024-39308
GHSA-8qgm-g2vv-vwvc
Jul 08, 2024
RailsAdmin Cross-site Scripting vulnerability in the list view
Medium
Network
Low
Low
ImpactRailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. The issue was originally reported in https://github.com/railsadminteam/rails_admin/issues/3686. PatchesUpgrade to 3.1.4. The vulnerability itself was patched in 3.1.3 but it has a functionality issue. Initially the vulnerability was thought to exist in versions before 3.0, but it didn't. 2.x users can stay on 2.2.1. Workarounds
Note: The view file created by this needs to be removed after upgrading RailsAdmin afterwards, unless this old view continue to be used. Only do this if you can't upgrade RailsAdmin now for a reason. Referenceshttps://owasp.org/www-community/attacks/xss/ https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-strip_tags Affected versions
3.0.0
3.0.0.beta
3.0.0.beta2
3.0.0.rc
3.0.0.rc2
3.0.0.rc3
3.0.0.rc4
3.1.0
3.1.0.beta
3.1.0.rc
3.1.0.rc2
3.1.1
+ 1 more Show less
3.1.2
Fixed in
3.1.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.1.0.rc
pre
Dependencies (6)
Changelog
Compare changes
|
|
3.1.0.beta
pre
1 CVE
CVE-2024-39308
GHSA-8qgm-g2vv-vwvc
Jul 08, 2024
RailsAdmin Cross-site Scripting vulnerability in the list view
Medium
Network
Low
Low
ImpactRailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. The issue was originally reported in https://github.com/railsadminteam/rails_admin/issues/3686. PatchesUpgrade to 3.1.4. The vulnerability itself was patched in 3.1.3 but it has a functionality issue. Initially the vulnerability was thought to exist in versions before 3.0, but it didn't. 2.x users can stay on 2.2.1. Workarounds
Note: The view file created by this needs to be removed after upgrading RailsAdmin afterwards, unless this old view continue to be used. Only do this if you can't upgrade RailsAdmin now for a reason. Referenceshttps://owasp.org/www-community/attacks/xss/ https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-strip_tags Affected versions
3.0.0
3.0.0.beta
3.0.0.beta2
3.0.0.rc
3.0.0.rc2
3.0.0.rc3
3.0.0.rc4
3.1.0
3.1.0.beta
3.1.0.rc
3.1.0.rc2
3.1.1
+ 1 more Show less
3.1.2
Fixed in
3.1.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.1.0.beta
pre
Dependencies (6)
Changelog
Compare changes
|
|
3.0.0
major
1 CVE
CVE-2024-39308
GHSA-8qgm-g2vv-vwvc
Jul 08, 2024
RailsAdmin Cross-site Scripting vulnerability in the list view
Medium
Network
Low
Low
ImpactRailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. The issue was originally reported in https://github.com/railsadminteam/rails_admin/issues/3686. PatchesUpgrade to 3.1.4. The vulnerability itself was patched in 3.1.3 but it has a functionality issue. Initially the vulnerability was thought to exist in versions before 3.0, but it didn't. 2.x users can stay on 2.2.1. Workarounds
Note: The view file created by this needs to be removed after upgrading RailsAdmin afterwards, unless this old view continue to be used. Only do this if you can't upgrade RailsAdmin now for a reason. Referenceshttps://owasp.org/www-community/attacks/xss/ https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-strip_tags Affected versions
3.0.0
3.0.0.beta
3.0.0.beta2
3.0.0.rc
3.0.0.rc2
3.0.0.rc3
3.0.0.rc4
3.1.0
3.1.0.beta
3.1.0.rc
3.1.0.rc2
3.1.1
+ 1 more Show less
3.1.2
Fixed in
3.1.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0
major
Dependencies (6)
Changelog
Compare changes
|
|
3.0.0.rc4
pre
1 CVE
CVE-2024-39308
GHSA-8qgm-g2vv-vwvc
Jul 08, 2024
RailsAdmin Cross-site Scripting vulnerability in the list view
Medium
Network
Low
Low
ImpactRailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. The issue was originally reported in https://github.com/railsadminteam/rails_admin/issues/3686. PatchesUpgrade to 3.1.4. The vulnerability itself was patched in 3.1.3 but it has a functionality issue. Initially the vulnerability was thought to exist in versions before 3.0, but it didn't. 2.x users can stay on 2.2.1. Workarounds
Note: The view file created by this needs to be removed after upgrading RailsAdmin afterwards, unless this old view continue to be used. Only do this if you can't upgrade RailsAdmin now for a reason. Referenceshttps://owasp.org/www-community/attacks/xss/ https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-strip_tags Affected versions
3.0.0
3.0.0.beta
3.0.0.beta2
3.0.0.rc
3.0.0.rc2
3.0.0.rc3
3.0.0.rc4
3.1.0
3.1.0.beta
3.1.0.rc
3.1.0.rc2
3.1.1
+ 1 more Show less
3.1.2
Fixed in
3.1.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0.rc4
pre
Dependencies (6)
Changelog
Compare changes
|
|
3.0.0.rc3
pre
1 CVE
CVE-2024-39308
GHSA-8qgm-g2vv-vwvc
Jul 08, 2024
RailsAdmin Cross-site Scripting vulnerability in the list view
Medium
Network
Low
Low
ImpactRailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. The issue was originally reported in https://github.com/railsadminteam/rails_admin/issues/3686. PatchesUpgrade to 3.1.4. The vulnerability itself was patched in 3.1.3 but it has a functionality issue. Initially the vulnerability was thought to exist in versions before 3.0, but it didn't. 2.x users can stay on 2.2.1. Workarounds
Note: The view file created by this needs to be removed after upgrading RailsAdmin afterwards, unless this old view continue to be used. Only do this if you can't upgrade RailsAdmin now for a reason. Referenceshttps://owasp.org/www-community/attacks/xss/ https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-strip_tags Affected versions
3.0.0
3.0.0.beta
3.0.0.beta2
3.0.0.rc
3.0.0.rc2
3.0.0.rc3
3.0.0.rc4
3.1.0
3.1.0.beta
3.1.0.rc
3.1.0.rc2
3.1.1
+ 1 more Show less
3.1.2
Fixed in
3.1.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0.rc3
pre
Dependencies (6)
Changelog
Compare changes
|
|
3.0.0.rc2
pre
1 CVE
CVE-2024-39308
GHSA-8qgm-g2vv-vwvc
Jul 08, 2024
RailsAdmin Cross-site Scripting vulnerability in the list view
Medium
Network
Low
Low
ImpactRailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. The issue was originally reported in https://github.com/railsadminteam/rails_admin/issues/3686. PatchesUpgrade to 3.1.4. The vulnerability itself was patched in 3.1.3 but it has a functionality issue. Initially the vulnerability was thought to exist in versions before 3.0, but it didn't. 2.x users can stay on 2.2.1. Workarounds
Note: The view file created by this needs to be removed after upgrading RailsAdmin afterwards, unless this old view continue to be used. Only do this if you can't upgrade RailsAdmin now for a reason. Referenceshttps://owasp.org/www-community/attacks/xss/ https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-strip_tags Affected versions
3.0.0
3.0.0.beta
3.0.0.beta2
3.0.0.rc
3.0.0.rc2
3.0.0.rc3
3.0.0.rc4
3.1.0
3.1.0.beta
3.1.0.rc
3.1.0.rc2
3.1.1
+ 1 more Show less
3.1.2
Fixed in
3.1.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0.rc2
pre
Dependencies (6)
Changelog
Compare changes
|
|
3.0.0.rc
pre
1 CVE
CVE-2024-39308
GHSA-8qgm-g2vv-vwvc
Jul 08, 2024
RailsAdmin Cross-site Scripting vulnerability in the list view
Medium
Network
Low
Low
ImpactRailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. The issue was originally reported in https://github.com/railsadminteam/rails_admin/issues/3686. PatchesUpgrade to 3.1.4. The vulnerability itself was patched in 3.1.3 but it has a functionality issue. Initially the vulnerability was thought to exist in versions before 3.0, but it didn't. 2.x users can stay on 2.2.1. Workarounds
Note: The view file created by this needs to be removed after upgrading RailsAdmin afterwards, unless this old view continue to be used. Only do this if you can't upgrade RailsAdmin now for a reason. Referenceshttps://owasp.org/www-community/attacks/xss/ https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-strip_tags Affected versions
3.0.0
3.0.0.beta
3.0.0.beta2
3.0.0.rc
3.0.0.rc2
3.0.0.rc3
3.0.0.rc4
3.1.0
3.1.0.beta
3.1.0.rc
3.1.0.rc2
3.1.1
+ 1 more Show less
3.1.2
Fixed in
3.1.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0.rc
pre
Dependencies (6)
Changelog
Compare changes
|
|
3.0.0.beta2
pre
1 CVE
CVE-2024-39308
GHSA-8qgm-g2vv-vwvc
Jul 08, 2024
RailsAdmin Cross-site Scripting vulnerability in the list view
Medium
Network
Low
Low
ImpactRailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. The issue was originally reported in https://github.com/railsadminteam/rails_admin/issues/3686. PatchesUpgrade to 3.1.4. The vulnerability itself was patched in 3.1.3 but it has a functionality issue. Initially the vulnerability was thought to exist in versions before 3.0, but it didn't. 2.x users can stay on 2.2.1. Workarounds
Note: The view file created by this needs to be removed after upgrading RailsAdmin afterwards, unless this old view continue to be used. Only do this if you can't upgrade RailsAdmin now for a reason. Referenceshttps://owasp.org/www-community/attacks/xss/ https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-strip_tags Affected versions
3.0.0
3.0.0.beta
3.0.0.beta2
3.0.0.rc
3.0.0.rc2
3.0.0.rc3
3.0.0.rc4
3.1.0
3.1.0.beta
3.1.0.rc
3.1.0.rc2
3.1.1
+ 1 more Show less
3.1.2
Fixed in
3.1.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0.beta2
pre
Dependencies (6)
Changelog
Compare changes
|
|
3.0.0.beta
pre
1 CVE
CVE-2024-39308
GHSA-8qgm-g2vv-vwvc
Jul 08, 2024
RailsAdmin Cross-site Scripting vulnerability in the list view
Medium
Network
Low
Low
ImpactRailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. The issue was originally reported in https://github.com/railsadminteam/rails_admin/issues/3686. PatchesUpgrade to 3.1.4. The vulnerability itself was patched in 3.1.3 but it has a functionality issue. Initially the vulnerability was thought to exist in versions before 3.0, but it didn't. 2.x users can stay on 2.2.1. Workarounds
Note: The view file created by this needs to be removed after upgrading RailsAdmin afterwards, unless this old view continue to be used. Only do this if you can't upgrade RailsAdmin now for a reason. Referenceshttps://owasp.org/www-community/attacks/xss/ https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-strip_tags Affected versions
3.0.0
3.0.0.beta
3.0.0.beta2
3.0.0.rc
3.0.0.rc2
3.0.0.rc3
3.0.0.rc4
3.1.0
3.1.0.beta
3.1.0.rc
3.1.0.rc2
3.1.1
+ 1 more Show less
3.1.2
Fixed in
3.1.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0.beta
pre
Dependencies (6)
Changelog
Compare changes
|
|
2.2.1
patch
|
2.2.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.2.0
minor
|
2.2.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.1.1
patch
|
2.1.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.1.0
minor
|
2.1.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
1.4.3
patch
|
1.4.3
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.0.2
patch
|
2.0.2
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.0.1
patch
1 CVE
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev |
2.0.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.0.0
major
1 CVE
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev |
2.0.0
major
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.0.0.rc
pre
|
2.0.0.rc
pre
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.0.0.beta
pre
|
2.0.0.beta
pre
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.4.2
patch
1 CVE
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev |
1.4.2
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.4.1
patch
1 CVE
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev |
1.4.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.4.0
minor
1 CVE
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev |
1.4.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.3.0
minor
1 CVE
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev |
1.3.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.2.0
minor
2 CVEs
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2017-12098
GHSA-pxr8-w3jq-rcwj
Mar 05, 2018
rails_admin ruby gem XSS
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 25 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
Fixed in
1.3.0
References
Updated Feb 20, 2024 · Source: OSV.dev |
1.2.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.1.1
patch
2 CVEs
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2017-12098
GHSA-pxr8-w3jq-rcwj
Mar 05, 2018
rails_admin ruby gem XSS
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 25 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
Fixed in
1.3.0
References
Updated Feb 20, 2024 · Source: OSV.dev |
1.1.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.1.0
minor
3 CVEs
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2016-10522
GHSA-pxqr-8v54-m2hj
Aug 08, 2018
Cross-site request forgery in rails_admin
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem. Affected versions
1.0.0
1.1.0
Fixed in
1.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-12098
GHSA-pxr8-w3jq-rcwj
Mar 05, 2018
rails_admin ruby gem XSS
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 25 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
Fixed in
1.3.0
References
Updated Feb 20, 2024 · Source: OSV.dev |
1.1.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.0.0
major
3 CVEs
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2016-10522
GHSA-pxqr-8v54-m2hj
Aug 08, 2018
Cross-site request forgery in rails_admin
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem. Affected versions
1.0.0
1.1.0
Fixed in
1.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-12098
GHSA-pxr8-w3jq-rcwj
Mar 05, 2018
rails_admin ruby gem XSS
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 25 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
Fixed in
1.3.0
References
Updated Feb 20, 2024 · Source: OSV.dev |
1.0.0
major
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.0.0.rc
pre
2 CVEs
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2017-12098
GHSA-pxr8-w3jq-rcwj
Mar 05, 2018
rails_admin ruby gem XSS
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 25 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
Fixed in
1.3.0
References
Updated Feb 20, 2024 · Source: OSV.dev |
1.0.0.rc
pre
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.8.1
minor
2 CVEs
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2017-12098
GHSA-pxr8-w3jq-rcwj
Mar 05, 2018
rails_admin ruby gem XSS
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 25 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
Fixed in
1.3.0
References
Updated Feb 20, 2024 · Source: OSV.dev |
0.8.1
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.7.0
minor
2 CVEs
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2017-12098
GHSA-pxr8-w3jq-rcwj
Mar 05, 2018
rails_admin ruby gem XSS
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 25 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
Fixed in
1.3.0
References
Updated Feb 20, 2024 · Source: OSV.dev |
0.7.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.6.8
patch
2 CVEs
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2017-12098
GHSA-pxr8-w3jq-rcwj
Mar 05, 2018
rails_admin ruby gem XSS
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 25 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
Fixed in
1.3.0
References
Updated Feb 20, 2024 · Source: OSV.dev |
0.6.8
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.6.7
patch
2 CVEs
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2017-12098
GHSA-pxr8-w3jq-rcwj
Mar 05, 2018
rails_admin ruby gem XSS
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 25 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
Fixed in
1.3.0
References
Updated Feb 20, 2024 · Source: OSV.dev |
0.6.7
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.6.6
patch
2 CVEs
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2017-12098
GHSA-pxr8-w3jq-rcwj
Mar 05, 2018
rails_admin ruby gem XSS
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 25 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
Fixed in
1.3.0
References
Updated Feb 20, 2024 · Source: OSV.dev |
0.6.6
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.6.5
patch
2 CVEs
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2017-12098
GHSA-pxr8-w3jq-rcwj
Mar 05, 2018
rails_admin ruby gem XSS
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 25 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
Fixed in
1.3.0
References
Updated Feb 20, 2024 · Source: OSV.dev |
0.6.5
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.6.4
patch
2 CVEs
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2017-12098
GHSA-pxr8-w3jq-rcwj
Mar 05, 2018
rails_admin ruby gem XSS
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 25 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
Fixed in
1.3.0
References
Updated Feb 20, 2024 · Source: OSV.dev |
0.6.4
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.6.3
patch
2 CVEs
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2017-12098
GHSA-pxr8-w3jq-rcwj
Mar 05, 2018
rails_admin ruby gem XSS
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 25 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
Fixed in
1.3.0
References
Updated Feb 20, 2024 · Source: OSV.dev |
0.6.3
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.6.2
patch
2 CVEs
CVE-2020-36190
GHSA-wjx2-7hqq-8h7m
Jan 14, 2021
rails_admin ruby gem XSS vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
Fixed in
1.4.3
2.0.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2017-12098
GHSA-pxr8-w3jq-rcwj
Mar 05, 2018
rails_admin ruby gem XSS
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
+ 25 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.8.1
1.0.0
1.0.0.rc
1.1.0
1.1.1
1.2.0
Fixed in
1.3.0
References
Updated Feb 20, 2024 · Source: OSV.dev |
0.6.2
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|