RubyGems package intelligence

actionpack Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the RubyGems package actionpack, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
2
Known exploited vulnerabilities affecting actionpack
In CISA KEV
2
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
actionpack KEVs with sensor-observed exploitation activity

Review actionpack exploitation against the versions you run

All two exploited actionpack vulnerabilities tracked here are also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested actionpack vulnerabilities

2 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2014-0130

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before...

In CISA 25 Mar 2022
CVE-2016-0752

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x...

In CISA 25 Mar 2022

Recurring weakness patterns

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') account for mapped occurrences across this actionpack KEV portfolio.

Browse all KEVs →