<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:12:33 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-01345</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-01345</link>
      <description>bdu:2021-01345</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-01345</guid>
    </item>
    <item>
      <title>BREW-travis-CVE-2020-8165 — ActiveSupport potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore</title>
      <link>https://cve.radiocsirt.org/vuln/brew-travis-cve-2020-8165</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: travis&lt;/p&gt;
&lt;p&gt;In ActiveSupport, there is potentially unexpected behaviour in the MemCacheStore and RedisCacheStore where, when
untrusted user input is written to the cache store using the `raw: true` parameter, re-reading the result
from the cache can evaluate the user input as a Marshalled object instead of plain text. Vulnerable code looks like:&lt;/p&gt;
&lt;p&gt;```
data = cache.fetch(&amp;#34;demo&amp;#34;, raw: true) { untrusted_string }
```
Versions Affected:  rails &amp;lt; 5.2.5, rails &amp;lt; 6.0.4
Not affected:       Applications not using MemCacheStore or RedisCacheStore. Applications that do not use the `raw` option when storing untrusted user input.
Fixed Versions:     rails &amp;gt;= 5.2.4.3, rails &amp;gt;= 6.0.3.1
  
Impact
------
Unmarshalling of untrusted user input can have impact up to and including RCE. At a minimum,
this vulnerability allows an attacker to inject untrusted Ruby objects into a web application.
In addition to upgrading to the latest versions of Rails, developers should ensure that whenever
they are calling `Rails.cache.fetch` they are using consistent values of the `raw` parameter for both
reading and writing, especially in the case of the RedisCacheStore which does not, prior to these changes,
detect if data was serialized using the raw option upon deserialization.&lt;/p&gt;
&lt;p&gt;Workarounds
-----------
It is recommended that application developers apply the suggested patch or upgrade to the latest release as
soon as possible. If this is not possible, we recommend ensuring that all user-provided strings cached using
the `ra…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: travis&lt;/p&gt;
&lt;p&gt;In ActiveSupport, there is potentially unexpected behaviour in the MemCacheStore and RedisCacheStore where, when
untrusted user input is written to the cache store using the `raw: true` parameter, re-reading the result
from the cache can evaluate the user input as a Marshalled object instead of plain text. Vulnerable code looks like:&lt;/p&gt;
&lt;p&gt;```
data = cache.fetch(&amp;#34;demo&amp;#34;, raw: true) { untrusted_string }
```
Versions Affected:  rails &amp;lt; 5.2.5, rails &amp;lt; 6.0.4
Not affected:       Applications not using MemCacheStore or RedisCacheStore. Applications that do not use the `raw` option when storing untrusted user input.
Fixed Versions:     rails &amp;gt;= 5.2.4.3, rails &amp;gt;= 6.0.3.1
  
Impact
------
Unmarshalling of untrusted user input can have impact up to and including RCE. At a minimum,
this vulnerability allows an attacker to inject untrusted Ruby objects into a web application.
In addition to upgrading to the latest versions of Rails, developers should ensure that whenever
they are calling `Rails.cache.fetch` they are using consistent values of the `raw` parameter for both
reading and writing, especially in the case of the RedisCacheStore which does not, prior to these changes,
detect if data was serialized using the raw option upon deserialization.&lt;/p&gt;
&lt;p&gt;Workarounds
-----------
It is recommended that application developers apply the suggested patch or upgrade to the latest release as
soon as possible. If this is not possible, we recommend ensuring that all user-provided strings cached using
the `ra…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-travis-cve-2020-8165</guid>
    </item>
    <item>
      <title>certfr-2020-avi-301 — De multiples vulnérabilités ont été découvertes dans Ruby on Rails.
Elles permettent à un attaquant de provoquer un pro…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-301</link>
      <description>certfr-2020-avi-301</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-301</guid>
    </item>
    <item>
      <title>cnvd-2020-39016</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-39016</link>
      <description>cnvd-2020-39016</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-39016</guid>
    </item>
    <item>
      <title>EUVD-2026-238774</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-238774</link>
      <description>EUVD-2026-238774</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-238774</guid>
    </item>
    <item>
      <title>fkie_cve-2020-8165</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8165</link>
      <description>&lt;p&gt;A deserialization of untrusted data vulnernerability exists in rails &amp;lt; 5.2.4.3, rails &amp;lt; 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A deserialization of untrusted data vulnernerability exists in rails &amp;lt; 5.2.4.3, rails &amp;lt; 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-8165</guid>
    </item>
    <item>
      <title>GHSA-2p68-f74v-9wc6 — ActiveSupport potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2p68-f74v-9wc6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: activesupport&lt;/p&gt;
&lt;p&gt;In ActiveSupport, there is potentially unexpected behaviour in the MemCacheStore and RedisCacheStore where, when
untrusted user input is written to the cache store using the `raw: true` parameter, re-reading the result
from the cache can evaluate the user input as a Marshalled object instead of plain text. Vulnerable code looks like:&lt;/p&gt;
&lt;p&gt;```
data = cache.fetch(&amp;#34;demo&amp;#34;, raw: true) { untrusted_string }
```
Versions Affected:  rails &amp;lt; 5.2.5, rails &amp;lt; 6.0.4
Not affected:       Applications not using MemCacheStore or RedisCacheStore. Applications that do not use the `raw` option when storing untrusted user input.
Fixed Versions:     rails &amp;gt;= 5.2.4.3, rails &amp;gt;= 6.0.3.1
  
Impact
------
Unmarshalling of untrusted user input can have impact up to and including RCE. At a minimum,
this vulnerability allows an attacker to inject untrusted Ruby objects into a web application.
In addition to upgrading to the latest versions of Rails, developers should ensure that whenever
they are calling `Rails.cache.fetch` they are using consistent values of the `raw` parameter for both
reading and writing, especially in the case of the RedisCacheStore which does not, prior to these changes,
detect if data was serialized using the raw option upon deserialization.&lt;/p&gt;
&lt;p&gt;Workarounds
-----------
It is recommended that application developers apply the suggested patch or upgrade to the latest release as
soon as possible. If this is not possible, we recommend ensuring that all user-provided strings cached using
the `ra…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: activesupport&lt;/p&gt;
&lt;p&gt;In ActiveSupport, there is potentially unexpected behaviour in the MemCacheStore and RedisCacheStore where, when
untrusted user input is written to the cache store using the `raw: true` parameter, re-reading the result
from the cache can evaluate the user input as a Marshalled object instead of plain text. Vulnerable code looks like:&lt;/p&gt;
&lt;p&gt;```
data = cache.fetch(&amp;#34;demo&amp;#34;, raw: true) { untrusted_string }
```
Versions Affected:  rails &amp;lt; 5.2.5, rails &amp;lt; 6.0.4
Not affected:       Applications not using MemCacheStore or RedisCacheStore. Applications that do not use the `raw` option when storing untrusted user input.
Fixed Versions:     rails &amp;gt;= 5.2.4.3, rails &amp;gt;= 6.0.3.1
  
Impact
------
Unmarshalling of untrusted user input can have impact up to and including RCE. At a minimum,
this vulnerability allows an attacker to inject untrusted Ruby objects into a web application.
In addition to upgrading to the latest versions of Rails, developers should ensure that whenever
they are calling `Rails.cache.fetch` they are using consistent values of the `raw` parameter for both
reading and writing, especially in the case of the RedisCacheStore which does not, prior to these changes,
detect if data was serialized using the raw option upon deserialization.&lt;/p&gt;
&lt;p&gt;Workarounds
-----------
It is recommended that application developers apply the suggested patch or upgrade to the latest release as
soon as possible. If this is not possible, we recommend ensuring that all user-provided strings cached using
the `ra…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2p68-f74v-9wc6</guid>
    </item>
    <item>
      <title>gsd-2020-8165</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-8165</link>
      <description>gsd-2020-8165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-8165</guid>
    </item>
    <item>
      <title>OESA-2021-1145 — rubygem-rails security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1145</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rubygem-rails&lt;/p&gt;
&lt;p&gt;Ruby on Rails is a full-stack web framework optimized for programmer happiness and sustainable productivity. It encourages beautiful code by favoring convention over configuration.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A deserialization of untrusted data vulnernerability exists in rails &amp;amp;lt; 5.2.4.3, rails &amp;amp;lt; 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.(CVE-2020-8165)&lt;/p&gt;
&lt;p&gt;A client side enforcement of server side security vulnerability exists in rails &amp;amp;lt; 5.2.4.2 and rails &amp;amp;lt; 6.0.3.1 ActiveStorages S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.(CVE-2020-8162)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rubygem-rails&lt;/p&gt;
&lt;p&gt;Ruby on Rails is a full-stack web framework optimized for programmer happiness and sustainable productivity. It encourages beautiful code by favoring convention over configuration.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A deserialization of untrusted data vulnernerability exists in rails &amp;amp;lt; 5.2.4.3, rails &amp;amp;lt; 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.(CVE-2020-8165)&lt;/p&gt;
&lt;p&gt;A client side enforcement of server side security vulnerability exists in rails &amp;amp;lt; 5.2.4.2 and rails &amp;amp;lt; 6.0.3.1 ActiveStorages S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.(CVE-2020-8162)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1145</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:1677-1 — Security update for rubygem-activesupport-5_1</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1677-1</link>
      <description>&lt;p&gt;Security update for rubygem-activesupport-5_1&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rubygem-activesupport-5_1&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:1677-1</guid>
    </item>
    <item>
      <title>RHSA-2021:1313 — Red Hat Security Advisory: Satellite 6.9 Release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:1313</link>
      <description>&lt;p&gt;rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses rubygem-rest-client: unsanitized application logging foreman: Managing repositories with their id via hammer does not respect the role filters rack-protection: Timing attack in authenticity_token.rb rubygem-rack: hijack sessions by using timing attacks targeting the session id python-psutil: Double free because of refcount mishandling rubygem-activestorage: circumvention of file size limits in ActiveStorage rubygem-actionpack: possible strong parameters bypass rubygem-activesupport: potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token rubygem-actionview: CSRF vulnerability in rails-ujs rubygem-rails: untrusted users able to run pending migrations in production django: potential SQL injection via &amp;#34;tolerance&amp;#34; parameter in GIS functions and aggregates on Oracle netty: compression/decompression codecs don&amp;#39;t enforce limits on buffer allocation sizes foreman: world-readable OMAPI secret through the ISC DHCP server rubygem-activeview: Cross-site scripting in translation helpers resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client&amp;#39;s WebApplicationException handling&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses rubygem-rest-client: unsanitized application logging foreman: Managing repositories with their id via hammer does not respect the role filters rack-protection: Timing attack in authenticity_token.rb rubygem-rack: hijack sessions by using timing attacks targeting the session id python-psutil: Double free because of refcount mishandling rubygem-activestorage: circumvention of file size limits in ActiveStorage rubygem-actionpack: possible strong parameters bypass rubygem-activesupport: potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token rubygem-actionview: CSRF vulnerability in rails-ujs rubygem-rails: untrusted users able to run pending migrations in production django: potential SQL injection via &amp;#34;tolerance&amp;#34; parameter in GIS functions and aggregates on Oracle netty: compression/decompression codecs don&amp;#39;t enforce limits on buffer allocation sizes foreman: world-readable OMAPI secret through the ISC DHCP server rubygem-activeview: Cross-site scripting in translation helpers resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client&amp;#39;s WebApplicationException handling&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:1313</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:2899-1 — Security update for rubygem-activesupport-5_1</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:2899-1</link>
      <description>&lt;p&gt;Security update for rubygem-activesupport-5_1&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rubygem-activesupport-5_1&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:2899-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-8165</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8165</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails&lt;/p&gt;
&lt;p&gt;A deserialization of untrusted data vulnernerability exists in rails &amp;lt; 5.2.4.3, rails &amp;lt; 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails&lt;/p&gt;
&lt;p&gt;A deserialization of untrusted data vulnernerability exists in rails &amp;lt; 5.2.4.3, rails &amp;lt; 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8165</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1093 — Ruby on Rails: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1093</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, beliebigen Programmcode auszuführen oder Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, beliebigen Programmcode auszuführen oder Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1093</guid>
    </item>
  </channel>
</rss>
