<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:23:49 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-08594</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-08594</link>
      <description>bdu:2025-08594</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-08594</guid>
    </item>
    <item>
      <title>certfr-2020-avi-380 — Une vulnérabilité a été découverte dans Ruby on Rails. Elle permet à un
attaquant de provoquer un contournement de la p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-380</link>
      <description>certfr-2020-avi-380</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-380</guid>
    </item>
    <item>
      <title>cnvd-2021-18397</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-18397</link>
      <description>cnvd-2021-18397</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-18397</guid>
    </item>
    <item>
      <title>EUVD-2026-38398</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-38398</link>
      <description>EUVD-2026-38398</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-38398</guid>
    </item>
    <item>
      <title>fkie_cve-2020-8185</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8185</link>
      <description>&lt;p&gt;A denial of service vulnerability exists in Rails &amp;lt;6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A denial of service vulnerability exists in Rails &amp;lt;6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-8185</guid>
    </item>
    <item>
      <title>GHSA-c6qr-h5vq-59jc — Untrusted users can run pending migrations in production in Rails</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c6qr-h5vq-59jc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: actionpack&lt;/p&gt;
&lt;p&gt;There is a vulnerability in versions of Rails prior to 6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.&lt;/p&gt;
&lt;p&gt;This vulnerability has been assigned the CVE identifier CVE-2020-8185.&lt;/p&gt;
&lt;p&gt;Versions Affected:  6.0.0 &amp;lt; rails &amp;lt; 6.0.3.2
Not affected:       Applications with `config.action_dispatch.show_exceptions = false` (this is not a default setting in production)
Fixed Versions:     rails &amp;gt;= 6.0.3.2&lt;/p&gt;
&lt;p&gt;Impact
------&lt;/p&gt;
&lt;p&gt;Using this issue, an attacker would be able to execute any migrations that are pending for a Rails app running in production mode. It is important to note that an attacker is limited to running migrations the application developer has already defined in their application and ones that have not already run.&lt;/p&gt;
&lt;p&gt;Workarounds
-----------&lt;/p&gt;
&lt;p&gt;Until such time as the patch can be applied, application developers should disable the ActionDispatch middleware in their production environment via a line such as this one in their config/environment/production.rb:&lt;/p&gt;
&lt;p&gt;`config.middleware.delete ActionDispatch::ActionableExceptions`&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: actionpack&lt;/p&gt;
&lt;p&gt;There is a vulnerability in versions of Rails prior to 6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.&lt;/p&gt;
&lt;p&gt;This vulnerability has been assigned the CVE identifier CVE-2020-8185.&lt;/p&gt;
&lt;p&gt;Versions Affected:  6.0.0 &amp;lt; rails &amp;lt; 6.0.3.2
Not affected:       Applications with `config.action_dispatch.show_exceptions = false` (this is not a default setting in production)
Fixed Versions:     rails &amp;gt;= 6.0.3.2&lt;/p&gt;
&lt;p&gt;Impact
------&lt;/p&gt;
&lt;p&gt;Using this issue, an attacker would be able to execute any migrations that are pending for a Rails app running in production mode. It is important to note that an attacker is limited to running migrations the application developer has already defined in their application and ones that have not already run.&lt;/p&gt;
&lt;p&gt;Workarounds
-----------&lt;/p&gt;
&lt;p&gt;Until such time as the patch can be applied, application developers should disable the ActionDispatch middleware in their production environment via a line such as this one in their config/environment/production.rb:&lt;/p&gt;
&lt;p&gt;`config.middleware.delete ActionDispatch::ActionableExceptions`&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c6qr-h5vq-59jc</guid>
    </item>
    <item>
      <title>gsd-2020-8185</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-8185</link>
      <description>gsd-2020-8185</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-8185</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:1993-1 — Security update for rmt-server</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1993-1</link>
      <description>&lt;p&gt;Security update for rmt-server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rmt-server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:1993-1</guid>
    </item>
    <item>
      <title>RHSA-2021:1313 — Red Hat Security Advisory: Satellite 6.9 Release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:1313</link>
      <description>&lt;p&gt;rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses rubygem-rest-client: unsanitized application logging foreman: Managing repositories with their id via hammer does not respect the role filters rack-protection: Timing attack in authenticity_token.rb rubygem-rack: hijack sessions by using timing attacks targeting the session id python-psutil: Double free because of refcount mishandling rubygem-activestorage: circumvention of file size limits in ActiveStorage rubygem-actionpack: possible strong parameters bypass rubygem-activesupport: potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token rubygem-actionview: CSRF vulnerability in rails-ujs rubygem-rails: untrusted users able to run pending migrations in production django: potential SQL injection via &amp;#34;tolerance&amp;#34; parameter in GIS functions and aggregates on Oracle netty: compression/decompression codecs don&amp;#39;t enforce limits on buffer allocation sizes foreman: world-readable OMAPI secret through the ISC DHCP server rubygem-activeview: Cross-site scripting in translation helpers resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client&amp;#39;s WebApplicationException handling&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses rubygem-rest-client: unsanitized application logging foreman: Managing repositories with their id via hammer does not respect the role filters rack-protection: Timing attack in authenticity_token.rb rubygem-rack: hijack sessions by using timing attacks targeting the session id python-psutil: Double free because of refcount mishandling rubygem-activestorage: circumvention of file size limits in ActiveStorage rubygem-actionpack: possible strong parameters bypass rubygem-activesupport: potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token rubygem-actionview: CSRF vulnerability in rails-ujs rubygem-rails: untrusted users able to run pending migrations in production django: potential SQL injection via &amp;#34;tolerance&amp;#34; parameter in GIS functions and aggregates on Oracle netty: compression/decompression codecs don&amp;#39;t enforce limits on buffer allocation sizes foreman: world-readable OMAPI secret through the ISC DHCP server rubygem-activeview: Cross-site scripting in translation helpers resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client&amp;#39;s WebApplicationException handling&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:1313</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:3036-1 — Security update for rmt-server</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:3036-1</link>
      <description>&lt;p&gt;Security update for rmt-server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rmt-server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:3036-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-8185</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8185</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails&lt;/p&gt;
&lt;p&gt;A denial of service vulnerability exists in Rails &amp;lt;6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails&lt;/p&gt;
&lt;p&gt;A denial of service vulnerability exists in Rails &amp;lt;6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8185</guid>
    </item>
  </channel>
</rss>
