<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T11:24:00.733493+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-08594</id>
    <title>bdu:2025-08594</title>
    <updated>2026-10-04T11:24:01.074830+00:00</updated>
    <content>bdu:2025-08594</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-08594"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-380</id>
    <title>certfr-2020-avi-380 — Une vulnérabilité a été découverte dans Ruby on Rails. Elle permet à un
attaquant de provoquer un contournement de la p…</title>
    <updated>2026-10-04T11:24:01.074878+00:00</updated>
    <content>certfr-2020-avi-380</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-380"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-18397</id>
    <title>cnvd-2021-18397</title>
    <updated>2026-10-04T11:24:01.074898+00:00</updated>
    <content>cnvd-2021-18397</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-18397"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-38398</id>
    <title>EUVD-2026-38398</title>
    <updated>2026-10-04T11:24:01.074912+00:00</updated>
    <content>EUVD-2026-38398</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-38398"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8185</id>
    <title>fkie_cve-2020-8185</title>
    <updated>2026-10-04T11:24:01.074922+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A denial of service vulnerability exists in Rails &lt;6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-8185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c6qr-h5vq-59jc</id>
    <title>GHSA-c6qr-h5vq-59jc — Untrusted users can run pending migrations in production in Rails</title>
    <updated>2026-10-04T11:24:01.074953+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: actionpack</p>
<p>There is a vulnerability in versions of Rails prior to 6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.</p>
<p>This vulnerability has been assigned the CVE identifier CVE-2020-8185.</p>
<p>Versions Affected:  6.0.0 &lt; rails &lt; 6.0.3.2
Not affected:       Applications with `config.action_dispatch.show_exceptions = false` (this is not a default setting in production)
Fixed Versions:     rails &gt;= 6.0.3.2</p>
<p>Impact
------</p>
<p>Using this issue, an attacker would be able to execute any migrations that are pending for a Rails app running in production mode. It is important to note that an attacker is limited to running migrations the application developer has already defined in their application and ones that have not already run.</p>
<p>Workarounds
-----------</p>
<p>Until such time as the patch can be applied, application developers should disable the ActionDispatch middleware in their production environment via a line such as this one in their config/environment/production.rb:</p>
<p>`config.middleware.delete ActionDispatch::ActionableExceptions`</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c6qr-h5vq-59jc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-8185</id>
    <title>gsd-2020-8185</title>
    <updated>2026-10-04T11:24:01.074990+00:00</updated>
    <content>gsd-2020-8185</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-8185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1993-1</id>
    <title>openSUSE-SU-2020:1993-1 — Security update for rmt-server</title>
    <updated>2026-10-04T11:24:01.075002+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rmt-server</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:1993-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:1313</id>
    <title>RHSA-2021:1313 — Red Hat Security Advisory: Satellite 6.9 Release</title>
    <updated>2026-10-04T11:24:01.075029+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses rubygem-rest-client: unsanitized application logging foreman: Managing repositories with their id via hammer does not respect the role filters rack-protection: Timing attack in authenticity_token.rb rubygem-rack: hijack sessions by using timing attacks targeting the session id python-psutil: Double free because of refcount mishandling rubygem-activestorage: circumvention of file size limits in ActiveStorage rubygem-actionpack: possible strong parameters bypass rubygem-activesupport: potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token rubygem-actionview: CSRF vulnerability in rails-ujs rubygem-rails: untrusted users able to run pending migrations in production django: potential SQL injection via "tolerance" parameter in GIS functions and aggregates on Oracle netty: compression/decompression codecs don't enforce limits on buffer allocation sizes foreman: world-readable OMAPI secret through the ISC DHCP server rubygem-activeview: Cross-site scripting in translation helpers resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client's WebApplicationException handling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:1313"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:3036-1</id>
    <title>SUSE-SU-2020:3036-1 — Security update for rmt-server</title>
    <updated>2026-10-04T11:24:01.075077+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rmt-server</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:3036-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8185</id>
    <title>UBUNTU-CVE-2020-8185</title>
    <updated>2026-10-04T11:24:01.075101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails</p>
<p>A denial of service vulnerability exists in Rails &lt;6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8185"/>
  </entry>
</feed>
