Known vulnerabilities in Ruby on Rails 3.2.15.rc3

Vendor: Rails
Software: Ruby on Rails
Version: 3.2.15.rc3
Software CPE: cpe:2.3:a:rails:ruby_on_rails:*:*:*:*:*:*:*:*
Total vulnerabilities: 7
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Ruby on Rails version 3.2.15.rc3 Ruby on Rails 3.2.15.rc3 is affected by 7 vulnerabilities: 1 high, 3 medium, 3 low Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU116155 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2014-0081
CWE-79 Medium
No
No
3.2.17, 4.0.3, 4.1.0.beta2 29.09.2025 SB2014022005
#VU8585 - Resource exhaustion
CVE-2016-0751
CWE-400 Low
No
No
- 22.09.2017 SB2016042501
SB2016013103
SB2016021014
#VU8569 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2016-2097
CWE-22 Medium
No
No
- 22.09.2017 SB2016031602
SB2016031003
SB2016032201
and 3 more
#VU8567 - Improper Control of Generation of Code ('Code Injection')
CVE-2016-2098
CWE-94 High
Public exploit available
No
- 16.03.2016 SB2016031601
SB2016031003
SB2016032301
and 7 more
#VU8568 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2016-0752
CWE-22 Medium
Public exploit available
Exploited
- 16.02.2016 SB2016021701
SB2016031003
SB2016042501
and 3 more
#VU8579 - Covert Timing Channel
CVE-2015-7576
CWE-385 Low
No
No
- 26.01.2016 SB2016012702
SB2016042501
SB2016013103
and 3 more
#VU8580 - Permissions, Privileges, and Access Controls
CVE-2015-7577
CWE-264 Low
No
No
- 26.01.2016 SB2016012702
SB2016042501
SB2016013106
and 1 more