{"api_version":"v1","generated_at":"2026-10-04T08:50:00+00:00","product":{"cve_count":27,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-publisher-not-identified-https-github-com-rails-rails-efbfbf836cf5","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"https://github.com/rails/rails","next_cursor":null,"observations":[{"affected":"7.0.4.1","affected_versions_present":true,"cve_id":"CVE-2023-22797","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22797","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-03-24T20:07:28.983Z","patch_url":"","primary_source":"","published":"2023-02-09T00:00:00.000Z"},{"affected":"6.1.7.1, 7.0.4.1","affected_versions_present":true,"cve_id":"CVE-2023-22796","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22796","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-11-27T15:16:00.509Z","patch_url":"https://discuss.rubyonrails.org/t/cve-2023-22796-possible-redos-based-dos-vulnerability-in-active-supports-underscore/82116","primary_source":"","published":"2023-02-09T00:00:00.000Z"},{"affected":"6.1.7.1, 7.0.4.1","affected_versions_present":true,"cve_id":"CVE-2023-22795","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22795","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T10:20:30.901Z","patch_url":"https://discuss.rubyonrails.org/t/cve-2023-22795-possible-redos-based-dos-vulnerability-in-action-dispatch/82118","primary_source":"","published":"2023-02-09T00:00:00.000Z"},{"affected":"6.0.6.1, 6.1.7.1, 7.0.4.1","affected_versions_present":true,"cve_id":"CVE-2023-22794","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22794","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T10:20:30.748Z","patch_url":"https://discuss.rubyonrails.org/t/cve-2023-22794-sql-injection-vulnerability-via-activerecord-comments/82117","primary_source":"","published":"2023-02-09T00:00:00.000Z"},{"affected":"6.0.6.1, 6.1.7.1, 7.0.4.1","affected_versions_present":true,"cve_id":"CVE-2023-22792","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22792","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-03-24T20:30:41.601Z","patch_url":"https://discuss.rubyonrails.org/t/cve-2023-22792-possible-redos-based-dos-vulnerability-in-action-dispatch/82115","primary_source":"","published":"2023-02-09T00:00:00.000Z"},{"affected":"7.0.4.1, 6.1.7.1","affected_versions_present":true,"cve_id":"CVE-2022-44566","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-44566","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-03-25T13:43:54.894Z","patch_url":"https://discuss.rubyonrails.org/t/cve-2022-44566-possible-denial-of-service-vulnerability-in-activerecords-postgresql-adapter/82119","primary_source":"","published":"2023-02-09T00:00:00.000Z"},{"affected":"7.0.3.1, 6.1.6.1, 6.0.5.1, 5.2.8.1","affected_versions_present":true,"cve_id":"CVE-2022-32224","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-32224","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-11T16:53:19.403Z","patch_url":"https://github.com/advisories/GHSA-3hhc-qp5v-9p2j","primary_source":"","published":"2022-12-05T00:00:00.000Z"},{"affected":"7.0.2.4, 6.1.5.1, 6.0.4.8, 5.2.7.1","affected_versions_present":true,"cve_id":"CVE-2022-27777","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-27777","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T05:32:59.808Z","patch_url":"https://discuss.rubyonrails.org/t/cve-2022-27777-possible-xss-vulnerability-in-action-view-tag-helpers/80534","primary_source":"","published":"2022-05-26T00:00:00.000Z"},{"affected":"7.0.2.4, 6.1.5.1, 6.0.4.8, 5.2.7.1","affected_versions_present":true,"cve_id":"CVE-2022-22577","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-22577","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T03:14:55.738Z","patch_url":"https://discuss.rubyonrails.org/t/cve-2022-22577-possible-xss-vulnerability-in-action-pack/80533","primary_source":"","published":"2022-05-26T00:00:00.000Z"},{"affected":"7.0.2.3, 6.1.4.7, 6.0.4.7, 5.2.6.3","affected_versions_present":true,"cve_id":"CVE-2022-21831","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-21831","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T02:53:36.300Z","patch_url":"https://github.com/advisories/GHSA-w749-p3v6-hccq","primary_source":"","published":"2022-05-26T00:00:00.000Z"},{"affected":"6.1.4.2, 6.0.4.2, 7.0.0.rc2","affected_versions_present":true,"cve_id":"CVE-2021-44528","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-44528","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T04:25:16.854Z","patch_url":"https://github.com/rails/rails/commit/0fccfb9a3097a9c4260c791f1a40b128517e7815","primary_source":"","published":"2022-01-07T00:00:00.000Z"},{"affected":"6.1.4.1, 6.0.4.1","affected_versions_present":true,"cve_id":"CVE-2021-22942","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-22942","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:58:26.009Z","patch_url":"http://www.openwall.com/lists/oss-security/2021/12/14/5","primary_source":"","published":"2021-10-18T00:00:00.000Z"},{"affected":"Fixed in 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6","affected_versions_present":true,"cve_id":"CVE-2021-22904","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-22904","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:58:25.438Z","patch_url":"https://discuss.rubyonrails.org/t/cve-2021-22904-possible-dos-vulnerability-in-action-controller-token-authentication/77869","primary_source":"","published":"2021-06-11T15:49:38.000Z"},{"affected":"Fixed in 6.1.3.2","affected_versions_present":true,"cve_id":"CVE-2021-22903","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-22903","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:58:25.786Z","patch_url":"https://discuss.rubyonrails.org/t/cve-2021-22903-possible-open-redirect-vulnerability-in-action-pack/77867","primary_source":"","published":"2021-06-11T15:49:38.000Z"},{"affected":"Fixed in 6.0.3.7, 6.1.3.2","affected_versions_present":true,"cve_id":"CVE-2021-22902","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-22902","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:58:25.713Z","patch_url":"https://discuss.rubyonrails.org/t/cve-2021-22902-possible-denial-of-service-vulnerability-in-action-dispatch/77866","primary_source":"","published":"2021-06-11T15:49:38.000Z"},{"affected":"6.1.3.1, 6.0.3.7, 5.2.4.6, 5.2.6","affected_versions_present":true,"cve_id":"CVE-2021-22885","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-22885","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-03T18:58:24.813Z","patch_url":"","primary_source":"","published":"2021-05-27T11:15:32.000Z"},{"affected":"Fixed in 6.1.2.1, 6.0.3.5","affected_versions_present":true,"cve_id":"CVE-2021-22881","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-22881","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:58:24.786Z","patch_url":"https://hackerone.com/reports/1047447","primary_source":"","published":"2021-02-11T16:12:34.000Z"},{"affected":"Fixed in 6.1.2.1, 6.0.3.5, 5.2.4.5","affected_versions_present":true,"cve_id":"CVE-2021-22880","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-22880","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:58:24.778Z","patch_url":"https://hackerone.com/reports/1023899","primary_source":"","published":"2021-02-11T16:11:22.000Z"},{"affected":"6.0.3.4","affected_versions_present":true,"cve_id":"CVE-2020-8264","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-8264","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T09:56:28.149Z","patch_url":"https://hackerone.com/reports/904059","primary_source":"","published":"2021-01-06T21:02:35.000Z"},{"affected":"Fixed in 5.2.4.3, 6.0.3.1","affected_versions_present":true,"cve_id":"CVE-2020-8166","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-8166","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-28T15:45:49.012Z","patch_url":"https://groups.google.com/g/rubyonrails-security/c/NOjKiGeXUgw","primary_source":"","published":"2020-07-02T18:35:17.000Z"},{"affected":"Fixed in 4.2.11.2","affected_versions_present":true,"cve_id":"CVE-2020-8163","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-8163","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T09:48:25.683Z","patch_url":"https://groups.google.com/g/rubyonrails-security/c/hWuKcHyoKh0","primary_source":"","published":"2020-07-02T18:35:12.000Z"},{"affected":"Fixed in 6.0.3.2","affected_versions_present":true,"cve_id":"CVE-2020-8185","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-8185","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T09:56:28.317Z","patch_url":"https://groups.google.com/g/rubyonrails-security/c/pAe9EV8gbM0","primary_source":"","published":"2020-07-02T18:35:06.000Z"},{"affected":"Fixed in 5.2.4.3, 6.0.3.1","affected_versions_present":true,"cve_id":"CVE-2020-8165","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-8165","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-05-09T20:03:28.191Z","patch_url":"https://hackerone.com/reports/413388","primary_source":"","published":"2020-06-19T17:05:30.000Z"},{"affected":"5.2.4.3, 6.0.3.1","affected_versions_present":true,"cve_id":"CVE-2020-8164","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-8164","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T09:48:25.653Z","patch_url":"https://hackerone.com/reports/292797","primary_source":"","published":"2020-06-19T17:04:13.000Z"},{"affected":"rails >= 5.2.4.3, rails >= 6.0.3.1","affected_versions_present":true,"cve_id":"CVE-2020-8162","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-8162","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T09:48:25.603Z","patch_url":"https://groups.google.com/g/rubyonrails-security/c/PjU3946mreQ","primary_source":"","published":"2020-06-19T17:02:42.000Z"},{"affected":"5.2.0 and later and before 5.2.1.1","affected_versions_present":true,"cve_id":"CVE-2018-16477","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-16477","fixed":"5.2.1.1.","last_modified":"2024-08-05T10:24:32.757Z","patch_url":"https://groups.google.com/d/msg/rubyonrails-security/3KQRnXDIuLg/mByx5KkqBAAJ","primary_source":"","published":"2018-11-30T19:00:00.000Z"},{"affected":"4.2.0 up to and before 4.2.11; 4.2.0 up to and before 5.0.7.1; 4.2.0 up to and before 5.1.6.1; 4.2.0 up to and before 5.2.1.1","affected_versions_present":true,"cve_id":"CVE-2018-16476","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-16476","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-05T10:24:32.802Z","patch_url":"https://groups.google.com/d/msg/rubyonrails-security/FL4dSdzr2zw/zjKVhF4qBAAJ","primary_source":"","published":"2018-11-30T19:00:00.000Z"}],"source_generated_at":"2026-10-04T06:24:23.053Z","vendor":"Publisher not identified"}}
