<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:27:40 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-05269</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-05269</link>
      <description>bdu:2021-05269</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-05269</guid>
    </item>
    <item>
      <title>certfr-2021-avi-352 — De multiples vulnérabilités ont été découvertes dans Ruby-on-rails.
Elles permettent à un attaquant de provoquer un dén…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-352</link>
      <description>certfr-2021-avi-352</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-352</guid>
    </item>
    <item>
      <title>cnvd-2021-44771</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-44771</link>
      <description>cnvd-2021-44771</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-44771</guid>
    </item>
    <item>
      <title>EUVD-2026-23195</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-23195</link>
      <description>EUVD-2026-23195</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-23195</guid>
    </item>
    <item>
      <title>fkie_cve-2021-22885</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22885</link>
      <description>&lt;p&gt;A possible information disclosure / unintended method execution vulnerability in Action Pack &amp;gt;= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A possible information disclosure / unintended method execution vulnerability in Action Pack &amp;gt;= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-22885</guid>
    </item>
    <item>
      <title>GHSA-hjg4-8q5f-x6fm — Action Pack contains Information Disclosure / Unintended Method Execution vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hjg4-8q5f-x6fm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: actionpack&lt;/p&gt;
&lt;p&gt;Impact
------
There is a possible information disclosure / unintended method execution vulnerability in Action Pack when using the `redirect_to` or `polymorphic_url` helper with untrusted user input.&lt;/p&gt;
&lt;p&gt;Vulnerable code will look like this.&lt;/p&gt;
&lt;p&gt;```
redirect_to(params[:some_param])
```&lt;/p&gt;
&lt;p&gt;All users running an affected release should either upgrade or use one of the workarounds immediately.&lt;/p&gt;
&lt;p&gt;Releases
--------
The FIXED releases are available at the normal locations.&lt;/p&gt;
&lt;p&gt;Workarounds
-----------
To work around this problem, it is recommended to use an allow list for valid parameters passed from the user.  For example,&lt;/p&gt;
&lt;p&gt;```ruby
private def check(param)
  case param
  when &amp;#34;valid&amp;#34;
    param
  else
    &amp;#34;/&amp;#34;
  end
end&lt;/p&gt;
&lt;p&gt;def index
  redirect_to(check(params[:some_param]))
end
```&lt;/p&gt;
&lt;p&gt;Or force the user input to be cast to a string like this,&lt;/p&gt;
&lt;p&gt;```ruby
def index
  redirect_to(params[:some_param].to_s)
end
```&lt;/p&gt;
&lt;p&gt;Patches
-------
To aid users who aren&amp;#39;t able to upgrade immediately we have provided patches for the two supported release series. They are in git-am format and consist of a single changeset.&lt;/p&gt;
&lt;p&gt;* 5-2-information-disclosure.patch - Patch for 5.2 series
* 6-0-information-disclosure.patch - Patch for 6.0 series
* 6-1-information-disclosure.patch - Patch for 6.1 series&lt;/p&gt;
&lt;p&gt;Please note that only the 5.2, 6.0, and 6.1 series are supported at present. Users of earlier unsupported releases are advised to upgrade as soon as possible as we cannot guarantee the continued availability of security fixes for unsup…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: actionpack&lt;/p&gt;
&lt;p&gt;Impact
------
There is a possible information disclosure / unintended method execution vulnerability in Action Pack when using the `redirect_to` or `polymorphic_url` helper with untrusted user input.&lt;/p&gt;
&lt;p&gt;Vulnerable code will look like this.&lt;/p&gt;
&lt;p&gt;```
redirect_to(params[:some_param])
```&lt;/p&gt;
&lt;p&gt;All users running an affected release should either upgrade or use one of the workarounds immediately.&lt;/p&gt;
&lt;p&gt;Releases
--------
The FIXED releases are available at the normal locations.&lt;/p&gt;
&lt;p&gt;Workarounds
-----------
To work around this problem, it is recommended to use an allow list for valid parameters passed from the user.  For example,&lt;/p&gt;
&lt;p&gt;```ruby
private def check(param)
  case param
  when &amp;#34;valid&amp;#34;
    param
  else
    &amp;#34;/&amp;#34;
  end
end&lt;/p&gt;
&lt;p&gt;def index
  redirect_to(check(params[:some_param]))
end
```&lt;/p&gt;
&lt;p&gt;Or force the user input to be cast to a string like this,&lt;/p&gt;
&lt;p&gt;```ruby
def index
  redirect_to(params[:some_param].to_s)
end
```&lt;/p&gt;
&lt;p&gt;Patches
-------
To aid users who aren&amp;#39;t able to upgrade immediately we have provided patches for the two supported release series. They are in git-am format and consist of a single changeset.&lt;/p&gt;
&lt;p&gt;* 5-2-information-disclosure.patch - Patch for 5.2 series
* 6-0-information-disclosure.patch - Patch for 6.0 series
* 6-1-information-disclosure.patch - Patch for 6.1 series&lt;/p&gt;
&lt;p&gt;Please note that only the 5.2, 6.0, and 6.1 series are supported at present. Users of earlier unsupported releases are advised to upgrade as soon as possible as we cannot guarantee the continued availability of security fixes for unsup…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hjg4-8q5f-x6fm</guid>
    </item>
    <item>
      <title>gsd-2021-22885</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-22885</link>
      <description>gsd-2021-22885</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-22885</guid>
    </item>
    <item>
      <title>OESA-2021-1236 — rubygem-actionpack security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1236</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rubygem-actionpack&lt;/p&gt;
&lt;p&gt;Eases web-request routing, handling, and response as a half-way front, half-way page controller. Implemented with specific emphasis on enabling easy unit/integration testing that doesn&amp;#39;t require a browser.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A possible information disclosure/unintended method execution vulnerability in Action Pack &amp;amp;gt;= 2.0.0 when using the redirect_to or polymorphic_urlhelper with untrusted user input.(CVE-2021-22885)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rubygem-actionpack&lt;/p&gt;
&lt;p&gt;Eases web-request routing, handling, and response as a half-way front, half-way page controller. Implemented with specific emphasis on enabling easy unit/integration testing that doesn&amp;#39;t require a browser.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A possible information disclosure/unintended method execution vulnerability in Action Pack &amp;amp;gt;= 2.0.0 when using the redirect_to or polymorphic_urlhelper with untrusted user input.(CVE-2021-22885)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1236</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:0797-1 — Security update for rubygem-actionpack-5_1</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0797-1</link>
      <description>&lt;p&gt;Security update for rubygem-actionpack-5_1&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rubygem-actionpack-5_1&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:0797-1</guid>
    </item>
    <item>
      <title>RHSA-2021:4702 — Red Hat Security Advisory: Satellite 6.10 Release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:4702</link>
      <description>&lt;p&gt;python-ecdsa: Unexpected and  undocumented exceptions during signature decoding python-ecdsa: DER encoding is not being verified in signatures rubygem-activerecord-session_store: hijack sessions by using timing attacks targeting the session id rake: OS Command Injection via egrep in Rake::FileList guava: local information disclosure via temporary directory created with unsafe permissions PyYAML: incomplete fix for CVE-2020-1747 rubygem-nokogiri: XML external entity injection via Nokogiri::XML::Schema Satellite: Azure compute resource secret_key leak to authenticated users foreman: possible man-in-the-middle in smart_proxy realm_freeipa Satellite: BMC controller credential leak via API python-aiohttp: Open redirect in aiohttp.web_middlewares.normalize_path_middleware rubygem-actionpack: Possible Information Disclosure / Unintended Method Execution in Action Pack rails: Possible Denial of Service vulnerability in Action Dispatch rails: Possible DoS Vulnerability in Action Controller Token Authentication django: potential directory-traversal via uploaded files rubygem-puma: incomplete fix for CVE-2019-16770 allows Denial of Service (DoS) django: Potential directory-traversal via uploaded files rubygem-addressable: ReDoS in templates django: Potential directory traversal via ``admindocs`` python-urllib3: ReDoS in the parsing of authority part of URL django: Possible indeterminate SSRF, RFI, and LFI attacks since validators accepted leading zeros in IPv4 addresses&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-ecdsa: Unexpected and  undocumented exceptions during signature decoding python-ecdsa: DER encoding is not being verified in signatures rubygem-activerecord-session_store: hijack sessions by using timing attacks targeting the session id rake: OS Command Injection via egrep in Rake::FileList guava: local information disclosure via temporary directory created with unsafe permissions PyYAML: incomplete fix for CVE-2020-1747 rubygem-nokogiri: XML external entity injection via Nokogiri::XML::Schema Satellite: Azure compute resource secret_key leak to authenticated users foreman: possible man-in-the-middle in smart_proxy realm_freeipa Satellite: BMC controller credential leak via API python-aiohttp: Open redirect in aiohttp.web_middlewares.normalize_path_middleware rubygem-actionpack: Possible Information Disclosure / Unintended Method Execution in Action Pack rails: Possible Denial of Service vulnerability in Action Dispatch rails: Possible DoS Vulnerability in Action Controller Token Authentication django: potential directory-traversal via uploaded files rubygem-puma: incomplete fix for CVE-2019-16770 allows Denial of Service (DoS) django: Potential directory-traversal via uploaded files rubygem-addressable: ReDoS in templates django: Potential directory traversal via ``admindocs`` python-urllib3: ReDoS in the parsing of authority part of URL django: Possible indeterminate SSRF, RFI, and LFI attacks since validators accepted leading zeros in IPv4 addresses&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:4702</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:1650-1 — Security update for rubygem-actionpack-4_2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:1650-1</link>
      <description>&lt;p&gt;Security update for rubygem-actionpack-4_2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rubygem-actionpack-4_2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:1650-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-22885</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22885</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails&lt;/p&gt;
&lt;p&gt;A possible information disclosure / unintended method execution vulnerability in Action Pack &amp;gt;= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails&lt;/p&gt;
&lt;p&gt;A possible information disclosure / unintended method execution vulnerability in Action Pack &amp;gt;= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22885</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0341 — Ruby on Rails: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0341</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um Informationen offenzulegen, einen Denial of Service Zustand auszulösen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um Informationen offenzulegen, einen Denial of Service Zustand auszulösen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0341</guid>
    </item>
  </channel>
</rss>
