12 open findings · 12 with upstream fix available
| Package | Version | Severity | CVE | Fix | Description | VEX |
|---|---|---|---|---|---|---|
| json | 2.18.0 | HIGH | GHSA-3m6g-2423-7cp3 | 2.19.2 | Ruby JSON has a format string injection vulnerability | — |
| net-imap | 0.6.2 | HIGH | GHSA-vcgp-9326-pqcp | 0.6.4 | net-imap vulnerable to STARTTLS stripping via invalid response timing | — |
| net-imap | 0.6.2 | MEDIUM | GHSA-75xq-5h9v-w6px | 0.6.4 | net-imap vulnerable to command Injection via unvalidated Symbol inputs | — |
| net-imap | 0.6.2 | MEDIUM | GHSA-hm49-wcqc-g2xg | 0.6.4 | net-imap vulnerable to command Injection via "raw" arguments to multiple commands | — |
| net-imap | 0.6.2 | MEDIUM | GHSA-87pf-fpwv-p7m7 | 0.6.4 | net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication | — |
| net-imap | 0.6.2 | MEDIUM | GHSA-46q3-7gv7-qmgg | 0.6.4.1 | Net::IMAP: Command Injection via ID command argument | — |
| net-imap | 0.6.2 | MEDIUM | GHSA-8p34-64r3-mwg8 | 0.6.4.1 | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument | — |
| net-imap | 0.6.4 | MEDIUM | GHSA-46q3-7gv7-qmgg | 0.6.4.1 | Net::IMAP: Command Injection via ID command argument | — |
| net-imap | 0.6.4 | MEDIUM | GHSA-8p34-64r3-mwg8 | 0.6.4.1 | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument | — |
| net-imap | 0.6.2 | LOW | GHSA-q2mw-fvj9-vvcw | 0.6.4 | net-imap has quadratic complexity when reading response literals | — |
| net-imap | 0.6.2 | LOW | GHSA-c4fp-cxrr-mj66 | 0.6.4.1 | Net::IMAP: Denial of Service via incomplete raw argument validation | — |
| net-imap | 0.6.4 | LOW | GHSA-c4fp-cxrr-mj66 | 0.6.4.1 | Net::IMAP: Denial of Service via incomplete raw argument validation | — |