David Hansson's vulnerability profile centers on Ruby on Rails, the widely adopted web application framework that serves as the foundation for numerous production applications. The durable signal reflects the framework's data-handling exposure, with recorded issues centered on sensitive information disclosure and related application-layer weaknesses. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by David Hansson over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5380MEDIUM Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to "URL-based sessio | Oct 19, 2007 | 6.8 | 19 | NO | NO |
CVE-2007-5379MEDIUM Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via the | Oct 19, 2007 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by David Hansson.
Media articles that mention a CVE ID that affects a product developed by David Hansson — matched by CVE ID, not by vendor name.