Vulnerabilities

    CVE-2015-7576 Timing attack vulnerability in basic authentication

    CVE-2014-7829 Arbitrary file existence disclosure

    CVE-2014-7818 Arbitrary file existence disclosure

    CVE-2013-6417 Incomplete fix to CVE-2013-0155 (Unsafe Query Generation Risk)

    CVE-2013-6416 XSS Vulnerability in simple_format helper

    CVE-2013-6415 XSS Vulnerability in number_to_currency

    CVE-2013-4491 Reflective XSS Vulnerability

    CVE-2013-1857 XSS Vulnerability in the `sanitize` helper

    CVE-2013-1855 XSS vulnerability in sanitize_css in Action Pack

    CVE-2013-0156 Multiple vulnerabilities in parameter parsing in Action Pack