<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:26:29.570317+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2016-avi-075</id>
    <title>certfr-2016-avi-075 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Ruby On Rails&lt;/span&gt;. Elles permettent à un att…</title>
    <updated>2026-10-02T21:26:29.580797+00:00</updated>
    <content>certfr-2016-avi-075</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2016-avi-075"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2016-01677</id>
    <title>cnvd-2016-01677</title>
    <updated>2026-10-02T21:26:29.580838+00:00</updated>
    <content>cnvd-2016-01677</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2016-01677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-82765</id>
    <title>EUVD-2026-82765</title>
    <updated>2026-10-02T21:26:29.580852+00:00</updated>
    <content>EUVD-2026-82765</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-82765"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2016-2097</id>
    <title>fkie_cve-2016-2097</title>
    <updated>2026-10-02T21:26:29.580869+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0752.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2016-2097"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vx9j-46rh-fqr8</id>
    <title>GHSA-vx9j-46rh-fqr8 — actionview contains Path Traversal vulnerability</title>
    <updated>2026-10-02T21:26:29.580912+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: actionview, RubyGems: actionpack</p>
<p>There is a possible directory traversal and information leak vulnerability in Action View. This was meant to be fixed on CVE-2016-0752. However the 3.2 patch was not covering all possible scenarios. This vulnerability has been assigned the CVE identifier CVE-2016-2097.</p>
<p>Versions Affected:  3.2.x, 4.0.x, 4.1.x
Not affected:       4.2+
Fixed Versions:     3.2.22.2, 4.1.14.2</p>
<p>Impact
------
Applications that pass unverified user input to the `render` method in a controller may be vulnerable to an information leak vulnerability.</p>
<p>Impacted code will look something like this:</p>
<p>```ruby
def index
  render params[:id]
end
```</p>
<p>Carefully crafted requests can cause the above code to render files from unexpected places like outside the application's view directory, and can possibly escalate this to a remote code execution attack.</p>
<p>All users running an affected release should either upgrade or use one of the workarounds immediately.</p>
<p>Releases
--------
The FIXED releases are available at the normal locations.</p>
<p>Workarounds
-----------
A workaround to this issue is to not pass arbitrary user input to the `render` method. Instead, verify that data before passing it to the `render` method.</p>
<p>For example, change this:</p>
<p>```ruby
def index
  render params[:id]
end
```</p>
<p>To this:</p>
<p>```ruby
def index
  render verify_template(params[:id])
end</p>
<p>private
def verify_template(name)
  # add verification logic particular to your application here
end
```</p>
<p>Patches
-------
To aid users who aren't able to upgrade…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vx9j-46rh-fqr8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2016-2097</id>
    <title>gsd-2016-2097</title>
    <updated>2026-10-02T21:26:29.580993+00:00</updated>
    <content>gsd-2016-2097</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2016-2097"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2016:0454</id>
    <title>RHSA-2016:0454 — Red Hat Security Advisory: ror40 security update</title>
    <updated>2026-10-02T21:26:29.581006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller rubygem-activerecord: Nested attributes rejection proc bypass in Active Record rubygem-actionpack: Object leak vulnerability for wildcard controller routes in Action Pack rubygem-actionpack: possible object leak and denial of service attack in Action Pack rubygem-actionpack: directory traversal flaw in Action View rubygem-actionpack: directory traversal in Action View, incomplete CVE-2016-0752 fix rubygem-actionpack: code injection vulnerability in Action View</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2016:0454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2016:0854-1</id>
    <title>SUSE-SU-2016:0854-1 — Security update for rubygem-actionview-4_1</title>
    <updated>2026-10-02T21:26:29.581031+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-actionview-4_1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2016:0854-1"/>
  </entry>
</feed>
