<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:15:22.625422+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-236767</id>
    <title>EUVD-2026-236767</title>
    <updated>2026-10-03T02:15:22.633421+00:00</updated>
    <content>EUVD-2026-236767</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-236767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-28362</id>
    <title>fkie_cve-2023-28362</title>
    <updated>2026-10-03T02:15:22.633452+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-28362"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4g8v-vg43-wpgf</id>
    <title>GHSA-4g8v-vg43-wpgf — Actionpack has possible cross-site scripting vulnerability via User Supplied Values to redirect_to</title>
    <updated>2026-10-03T02:15:22.633482+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: actionpack</p>
<p>The `redirect_to` method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header. This vulnerability has been assigned the CVE identifier CVE-2023-28362.</p>
<p>Versions Affected: All. Not affected: None Fixed Versions: 7.0.5.1, 6.1.7.4</p>
<p># Impact</p>
<p>This introduces the potential for a Cross-site-scripting (XSS) payload to be delivered on the now static redirection page. Note that this both requires user interaction and for a Rails app to be configured to allow redirects to external hosts (defaults to false in Rails &gt;= 7.0.x).</p>
<p># Releases</p>
<p>The FIXED releases are available at the normal locations.</p>
<p># Workarounds</p>
<p>Avoid providing user supplied URLs with arbitrary schemes to the `redirect_to` method.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4g8v-vg43-wpgf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-28362</id>
    <title>gsd-2023-28362</title>
    <updated>2026-10-03T02:15:22.633515+00:00</updated>
    <content>gsd-2023-28362</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-28362"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2465</id>
    <title>OESA-2024-2465 — rubygem-actionpack security update</title>
    <updated>2026-10-03T02:15:22.633527+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: rubygem-actionpack</p>
<p>Eases web-request routing, handling, and response as a half-way front, half-way page controller. Implemented with specific emphasis on enabling easy unit/integration testing that doesn&amp;apos;t require a browser.

Security Fix(es):

A Cross-site Scripting (XSS) vulnerability was found in Actionpack due to improper sanitization of user-supplied values. This allows provided values to contain characters that are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned location header.(CVE-2023-28362)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:7851</id>
    <title>RHSA-2023:7851 — Red Hat Security Advisory: Satellite 6.14.1 Async Security Update</title>
    <updated>2026-10-03T02:15:22.633550+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>foreman: World readable file containing secrets actionpack: Possible XSS via User Supplied Values to redirect_to GitPython: Blind local file inclusion python-urllib3: Cookie request header isn't stripped during cross-origin redirects urllib3: Request body not stripped after redirect from 303 status changes request method to GET</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:7851"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:3229-1</id>
    <title>SUSE-SU-2023:3229-1 — Security update for rubygem-actionpack-5_1</title>
    <updated>2026-10-03T02:15:22.633571+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-actionpack-5_1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:3229-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28362</id>
    <title>UBUNTU-CVE-2023-28362</title>
    <updated>2026-10-03T02:15:22.633585+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails</p>
<p>The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28362"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1577</id>
    <title>WID-SEC-W-2023-1577 — Ruby on Rails: Schwachstelle ermöglicht Cross-Site Scripting</title>
    <updated>2026-10-03T02:15:22.633610+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby on Rails ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1577"/>
  </entry>
</feed>
