Vulnerability Name:

CVE-2015-7576 (CCN-110099)

Assigned:2015-09-29
Published:2016-01-25
Updated:2019-08-08
Summary:The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.
CVSS v3 Severity:3.7 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
3.2 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-254
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2015-7576

Source: FEDORA
Type: UNKNOWN
FEDORA-2016-94e71ee673

Source: FEDORA
Type: UNKNOWN
FEDORA-2016-cb30088b06

Source: FEDORA
Type: UNKNOWN
FEDORA-2016-f486068393

Source: FEDORA
Type: UNKNOWN
FEDORA-2016-3ede04cd79

Source: SUSE
Type: UNKNOWN
SUSE-SU-2016:1146

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2016:0363

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2016:0372

Source: CCN
Type: RHSA-2016-0296
Important: rh-ror41 security update

Source: REDHAT
Type: UNKNOWN
RHSA-2016:0296

Source: CCN
Type: RHSA-2016-0454
Important: ror40 security update

Source: CCN
Type: RHSA-2016-0455
Important: ruby193 security update

Source: CCN
Type: Ruby on Rails Web Site
Rails 5.0.0.beta1.1, 4.2.5.1, 4.1.14.1, 3.2.22.1, and rails-html-sanitizer 1.0.3 have been released!

Source: DEBIAN
Type: UNKNOWN
DSA-3464

Source: CCN
Type: IBM Security Bulletin 1985099 (License Metric Tool)
Security Bulletin: Vulnerabilities in Ruby on Rails affect IBM License Metric Tool v9, IBM BigFix Inventory v9 and IBM Endpoint Manager for Software Use Analysis v9 & v2.2

Source: MLIST
Type: UNKNOWN
[oss-security] 20160125 [CVE-2015-7576] Timing attack vulnerability in basic authentication in Action Controller.

Source: BID
Type: UNKNOWN
81803

Source: CCN
Type: BID-81803
Ruby On Rails Action Controller CVE-2015-7576 Information Disclosure Vulnerability

Source: SECTRACK
Type: UNKNOWN
1034816

Source: XF
Type: UNKNOWN
rails-cve20157576-info-disc(110099)

Source: MLIST
Type: UNKNOWN
[ruby-security-ann] 20160125 [CVE-2015-7576] Timing attack vulnerability in basic authentication in Action Controller.

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2015-7576

Vulnerable Configuration:Configuration 1:
  • cpe:/a:rubyonrails:rails:4.0.0:-:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.0:beta:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.0:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.0:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.1:-:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.1:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.1:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.1:rc3:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.1:rc4:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.4:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.6:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.6:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.6:rc3:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.8:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.9:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.10:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.0.10:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.0:-:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.0:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.0:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.2:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.2:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.2:rc3:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.6:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.6:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.6:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.8:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.9:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.9:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.10:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.10:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.10:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.10:rc3:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.10:rc4:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.12:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.12:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.13:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.13:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.14:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.14:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.1.14:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.0:beta3:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.0:beta4:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.0:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.0:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.0:rc3:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.1:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.1:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.1:rc3:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.1:rc4:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.3:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.4:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.5:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.5:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:4.2.5:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:5.0.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* (Version <= 3.2.22)
  • OR cpe:/a:rubyonrails:ruby_on_rails:4.0.10:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:ruby_on_rails:4.0.11:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:ruby_on_rails:4.0.11.1:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:ruby_on_rails:4.0.12:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:ruby_on_rails:4.0.13:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:ruby_on_rails:4.0.13:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:ruby_on_rails:4.1.11:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:rubyonrails:rails:3.0.0:-:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:license_metric_tool:9.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:license_metric_tool:9.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:license_metric_tool:9.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:license_metric_tool:9.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20157576
    V
    CVE-2015-7576
    2022-05-22
    oval:org.opensuse.security:def:14061
    P
    xen-4.7.0_12-23.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14723
    P
    pam_ssh-2.0-1.39 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13863
    P
    libHX28-3.18-1.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13992
    P
    openvpn-2.3.8-16.6.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14085
    P
    apache2-mod_jk-1.2.40-5.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13816
    P
    evince-3.20.1-5.66 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13899
    P
    libfreetype6-2.6.3-7.8.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14072
    P
    yast2-users-3.1.57-16.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14745
    P
    python-doc-2.7.13-28.11.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13880
    P
    libXtst6-1.2.2-3.59 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14017
    P
    python-libxml2-2.9.4-27.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:38206
    P
    Security update for libsndfile (Critical)
    2021-07-27
    oval:org.opensuse.security:def:38116
    P
    Security update for curl (Moderate)
    2021-06-30
    oval:org.opensuse.security:def:38425
    P
    Security update for SUSE Manager Client Tools (Important)
    2021-06-21
    oval:org.opensuse.security:def:13726
    P
    squid-3.3.13-4.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13718
    P
    rsyslog-8.4.0-8.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13748
    P
    wpa_supplicant-2.2-8.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:38366
    P
    Security update for xorg-x11-server (Important)
    2021-04-13
    oval:org.opensuse.security:def:39265
    P
    Security update for openldap2 (Important)
    2021-03-04
    oval:org.opensuse.security:def:26445
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:27361
    P
    NetworkManager-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38541
    P
    apache-commons-beanutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26936
    P
    ldapsmb on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27273
    P
    procmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26718
    P
    hplip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27614
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:37821
    P
    ibus-chewing on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27561
    P
    rubygem-rack-1_4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27010
    P
    pcsc-lite on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27712
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:26932
    P
    krb5-doc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27667
    P
    Security update for rubygem-activesupport-3_2
    2020-12-01
    oval:org.opensuse.security:def:26433
    P
    Security update for MozillaThunderbird (Critical)
    2020-12-01
    oval:org.opensuse.security:def:27649
    P
    Security update for lighttpd
    2020-12-01
    oval:org.opensuse.security:def:27140
    P
    gstreamer-0_10-plugins-base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28384
    P
    Security update for rubygem-activesupport-3_2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27011
    P
    perl-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28345
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26943
    P
    libcap-progs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27362
    P
    OpenEXR-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27209
    P
    libproxy0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27277
    P
    python-imaging on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38513
    P
    w3m on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27216
    P
    libsnmp15-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27615
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:26637
    P
    ruby on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27565
    P
    rxvt-unicode on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39223
    P
    openconnect on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37737
    P
    autofs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27508
    P
    libxslt-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26937
    P
    libMagickCore1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26859
    P
    acpid on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27668
    P
    Security update for rubygem-json_pure
    2020-12-01
    oval:org.opensuse.security:def:26931
    P
    krb5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38059
    P
    rzsz on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27653
    P
    Security update for libfreebl3
    2020-12-01
    oval:org.opensuse.security:def:27112
    P
    e2fsprogs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28385
    P
    Security update for rubygem-activesupport-3_2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27012
    P
    perl-HTML-Parser on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28349
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26947
    P
    libexif on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27707
    P
    Security update for augeas (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37725
    P
    ant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27278
    P
    python-lxml on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27165
    P
    krb5-plugin-kdb-ldap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27220
    P
    libtasn1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38474
    P
    rsyslog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27135
    P
    gmime on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27566
    P
    sendmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27882
    P
    Security update for rubygem-activesupport-3_2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26509
    P
    Security update for cacti, cacti-spine (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27512
    P
    lynx on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38585
    P
    ecryptfs-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37726
    P
    apache-commons-beanutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27357
    P
    ImageMagick on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26935
    P
    lcms on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26775
    P
    libxslt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27654
    P
    Security update for Perl
    2020-12-01
    oval:org.opensuse.security:def:37958
    P
    libsmi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27610
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:27063
    P
    xterm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28350
    P
    Recommended update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26948
    P
    libexiv2-4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27711
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:26434
    P
    Security update for pdns (Important)
    2020-12-01
    oval:org.opensuse.security:def:27663
    P
    Security update for rubygem-actionpack-2_1
    2020-12-01
    oval:org.opensuse.security:def:27221
    P
    libtevent0-x86 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27151
    P
    jakarta-commons-httpclient3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27139
    P
    gpgme on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28380
    P
    Security update for rubygem-actionpack-3_2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27007
    P
    pam_mount on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27513
    P
    lzo-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27847
    P
    Security update for openldap2 (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:201575760000000
    V
    CVE-2015-7576 on Ubuntu 18.04 LTS (bionic) - medium.
    2016-02-16
    oval:com.ubuntu.xenial:def:201575760000000
    V
    CVE-2015-7576 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-02-16
    oval:com.ubuntu.disco:def:201575760000000
    V
    CVE-2015-7576 on Ubuntu 19.04 (disco) - medium.
    2016-02-16
    oval:com.ubuntu.cosmic:def:201575760000000
    V
    CVE-2015-7576 on Ubuntu 18.10 (cosmic) - medium.
    2016-02-15
    oval:com.ubuntu.artful:def:20157576000
    V
    CVE-2015-7576 on Ubuntu 17.10 (artful) - medium.
    2016-02-15
    oval:com.ubuntu.trusty:def:20157576000
    V
    CVE-2015-7576 on Ubuntu 14.04 LTS (trusty) - medium.
    2016-02-15
    oval:com.ubuntu.bionic:def:20157576000
    V
    CVE-2015-7576 on Ubuntu 18.04 LTS (bionic) - medium.
    2016-02-15
    oval:com.ubuntu.xenial:def:20157576000
    V
    CVE-2015-7576 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-02-15
    oval:com.ubuntu.cosmic:def:20157576000
    V
    CVE-2015-7576 on Ubuntu 18.10 (cosmic) - medium.
    2016-02-15
    oval:com.ubuntu.precise:def:20157576000
    V
    CVE-2015-7576 on Ubuntu 12.04 LTS (precise) - medium.
    2016-02-15
    BACK
    rubyonrails rails 4.0.0 -
    rubyonrails rails 4.0.0 beta
    rubyonrails rails 4.0.0 rc1
    rubyonrails rails 4.0.0 rc2
    rubyonrails rails 4.0.1 -
    rubyonrails rails 4.0.1 rc1
    rubyonrails rails 4.0.1 rc2
    rubyonrails rails 4.0.1 rc3
    rubyonrails rails 4.0.1 rc4
    rubyonrails rails 4.0.2
    rubyonrails rails 4.0.3
    rubyonrails rails 4.0.4
    rubyonrails rails 4.0.4 rc1
    rubyonrails rails 4.0.5
    rubyonrails rails 4.0.6
    rubyonrails rails 4.0.6 rc1
    rubyonrails rails 4.0.6 rc2
    rubyonrails rails 4.0.6 rc3
    rubyonrails rails 4.0.7
    rubyonrails rails 4.0.8
    rubyonrails rails 4.0.9
    rubyonrails rails 4.0.10
    rubyonrails rails 4.0.10 rc1
    rubyonrails rails 4.1.0 -
    rubyonrails rails 4.1.0 beta1
    rubyonrails rails 4.1.0 beta2
    rubyonrails rails 4.1.0 rc1
    rubyonrails rails 4.1.0 rc2
    rubyonrails rails 4.1.1
    rubyonrails rails 4.1.2
    rubyonrails rails 4.1.2 rc1
    rubyonrails rails 4.1.2 rc2
    rubyonrails rails 4.1.2 rc3
    rubyonrails rails 4.1.3
    rubyonrails rails 4.1.4
    rubyonrails rails 4.1.5
    rubyonrails rails 4.1.6
    rubyonrails rails 4.1.6 rc1
    rubyonrails rails 4.1.6 rc2
    rubyonrails rails 4.1.7
    rubyonrails rails 4.1.7.1
    rubyonrails rails 4.1.8
    rubyonrails rails 4.1.9
    rubyonrails rails 4.1.9 rc1
    rubyonrails rails 4.1.10
    rubyonrails rails 4.1.10 rc1
    rubyonrails rails 4.1.10 rc2
    rubyonrails rails 4.1.10 rc3
    rubyonrails rails 4.1.10 rc4
    rubyonrails rails 4.1.12
    rubyonrails rails 4.1.12 rc1
    rubyonrails rails 4.1.13
    rubyonrails rails 4.1.13 rc1
    rubyonrails rails 4.1.14
    rubyonrails rails 4.1.14 rc1
    rubyonrails rails 4.1.14 rc2
    rubyonrails rails 4.2.0
    rubyonrails rails 4.2.0 beta1
    rubyonrails rails 4.2.0 beta2
    rubyonrails rails 4.2.0 beta3
    rubyonrails rails 4.2.0 beta4
    rubyonrails rails 4.2.0 rc1
    rubyonrails rails 4.2.0 rc2
    rubyonrails rails 4.2.0 rc3
    rubyonrails rails 4.2.1
    rubyonrails rails 4.2.1 rc1
    rubyonrails rails 4.2.1 rc2
    rubyonrails rails 4.2.1 rc3
    rubyonrails rails 4.2.1 rc4
    rubyonrails rails 4.2.2
    rubyonrails rails 4.2.3
    rubyonrails rails 4.2.3 rc1
    rubyonrails rails 4.2.4
    rubyonrails rails 4.2.4 rc1
    rubyonrails rails 4.2.5
    rubyonrails rails 4.2.5 rc1
    rubyonrails rails 4.2.5 rc2
    rubyonrails rails 5.0.0 beta1
    rubyonrails ruby on rails *
    rubyonrails ruby on rails 4.0.10 rc2
    rubyonrails ruby on rails 4.0.11
    rubyonrails ruby on rails 4.0.11.1
    rubyonrails ruby on rails 4.0.12
    rubyonrails ruby on rails 4.0.13
    rubyonrails ruby on rails 4.0.13 rc1
    rubyonrails ruby on rails 4.1.11
    rubyonrails ruby on rails 3.0
    ibm license metric tool 9.0
    ibm license metric tool 9.0.1
    ibm license metric tool 9.1
    ibm license metric tool 9.2