Snorby/snorby

Snorby/snorby

Releases36
Frequency3 weeks 4 days
Last Release
Stars1.01K
Ruby On Rails Application For Network Security Monitoring

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in app/views/events/_menu.html.erb in Snorby 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the title (cls.name variable) when creating a classification.

6.8 MEDIUM

Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.