<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:29:23 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-00440</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-00440</link>
      <description>bdu:2019-00440</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-00440</guid>
    </item>
    <item>
      <title>certfr-2018-avi-297 — Une vulnérabilité a été découverte dans Ruby On Rails. Elle permet à un
attaquant de provoquer une atteinte à la confid…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2018-avi-297</link>
      <description>certfr-2018-avi-297</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2018-avi-297</guid>
    </item>
    <item>
      <title>EUVD-2026-168347</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-168347</link>
      <description>EUVD-2026-168347</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-168347</guid>
    </item>
    <item>
      <title>fkie_cve-2018-3760</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-3760</link>
      <description>&lt;p&gt;There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application&amp;#39;s root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application&amp;#39;s root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-3760</guid>
    </item>
    <item>
      <title>GHSA-pr3h-jjhj-573x — Sprockets path traversal leads to information leak</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pr3h-jjhj-573x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: sprockets&lt;/p&gt;
&lt;p&gt;Specially crafted requests can be used to access files that exist on the filesystem that is outside an application&amp;#39;s root directory, when the Sprockets server is used in production.
  
All users running an affected release should either upgrade or use one of the work arounds immediately.
  
### Workaround:
  
In Rails applications, work around this issue, set `config.assets.compile = false` and `config.public_file_server.enabled = true` in an initializer and precompile the assets.&lt;/p&gt;
&lt;p&gt;This work around will not be possible in all hosting environments and upgrading is advised.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: sprockets&lt;/p&gt;
&lt;p&gt;Specially crafted requests can be used to access files that exist on the filesystem that is outside an application&amp;#39;s root directory, when the Sprockets server is used in production.
  
All users running an affected release should either upgrade or use one of the work arounds immediately.
  
### Workaround:
  
In Rails applications, work around this issue, set `config.assets.compile = false` and `config.public_file_server.enabled = true` in an initializer and precompile the assets.&lt;/p&gt;
&lt;p&gt;This work around will not be possible in all hosting environments and upgrading is advised.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pr3h-jjhj-573x</guid>
    </item>
    <item>
      <title>gsd-2018-3760</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-3760</link>
      <description>gsd-2018-3760</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-3760</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11354-1 — ruby2.7-rubygem-sprockets-4.0.2-1.7 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11354-1</link>
      <description>&lt;p&gt;ruby2.7-rubygem-sprockets-4.0.2-1.7 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby2.7-rubygem-sprockets-4.0.2-1.7 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11354-1</guid>
    </item>
    <item>
      <title>RHSA-2018:2244 — Red Hat Security Advisory: rh-ror42-rubygem-sprockets security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:2244</link>
      <description>&lt;p&gt;rubygem-sprockets: Path traversal in forbidden_request?() can allow remote attackers to read arbitrary files&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rubygem-sprockets: Path traversal in forbidden_request?() can allow remote attackers to read arbitrary files&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:2244</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:1994-1 — Security update for rubygem-sprockets</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:1994-1</link>
      <description>&lt;p&gt;Security update for rubygem-sprockets&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rubygem-sprockets&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:1994-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-3760</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-3760</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-sprockets, Ubuntu:18.04:LTS: ruby-sprockets&lt;/p&gt;
&lt;p&gt;There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application&amp;#39;s root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-sprockets, Ubuntu:18.04:LTS: ruby-sprockets&lt;/p&gt;
&lt;p&gt;There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application&amp;#39;s root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-3760</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1086 — Red Hat Enterprise Linux: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1086</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1086</guid>
    </item>
  </channel>
</rss>
