<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:26:21 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-04201</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-04201</link>
      <description>bdu:2022-04201</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-04201</guid>
    </item>
    <item>
      <title>BREW-mailcatcher-CVE-2022-30123 — Possible shell escape sequence injection vulnerability in Rack</title>
      <link>https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2022-30123</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: mailcatcher&lt;/p&gt;
&lt;p&gt;There is a possible shell escape sequence injection vulnerability in the Lint
and CommonLogger components of Rack.  This vulnerability has been assigned the
CVE identifier CVE-2022-30123.&lt;/p&gt;
&lt;p&gt;Versions Affected:  All.
Not affected:       None
Fixed Versions:     2.0.9.1, 2.1.4.1, 2.2.3.1&lt;/p&gt;
&lt;p&gt;## Impact
Carefully crafted requests can cause shell escape sequences to be written to
the terminal via Rack&amp;#39;s Lint middleware and CommonLogger middleware.  These
escape sequences can be leveraged to possibly execute commands in the victim&amp;#39;s
terminal.&lt;/p&gt;
&lt;p&gt;Impacted applications will have either of these middleware installed, and
vulnerable apps may have something like this:&lt;/p&gt;
&lt;p&gt;```
use Rack::Lint
```&lt;/p&gt;
&lt;p&gt;Or&lt;/p&gt;
&lt;p&gt;```
use Rack::CommonLogger
```&lt;/p&gt;
&lt;p&gt;All users running an affected release should either upgrade or use one of the
workarounds immediately.&lt;/p&gt;
&lt;p&gt;## Workarounds
Remove these middleware from your application&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: mailcatcher&lt;/p&gt;
&lt;p&gt;There is a possible shell escape sequence injection vulnerability in the Lint
and CommonLogger components of Rack.  This vulnerability has been assigned the
CVE identifier CVE-2022-30123.&lt;/p&gt;
&lt;p&gt;Versions Affected:  All.
Not affected:       None
Fixed Versions:     2.0.9.1, 2.1.4.1, 2.2.3.1&lt;/p&gt;
&lt;p&gt;## Impact
Carefully crafted requests can cause shell escape sequences to be written to
the terminal via Rack&amp;#39;s Lint middleware and CommonLogger middleware.  These
escape sequences can be leveraged to possibly execute commands in the victim&amp;#39;s
terminal.&lt;/p&gt;
&lt;p&gt;Impacted applications will have either of these middleware installed, and
vulnerable apps may have something like this:&lt;/p&gt;
&lt;p&gt;```
use Rack::Lint
```&lt;/p&gt;
&lt;p&gt;Or&lt;/p&gt;
&lt;p&gt;```
use Rack::CommonLogger
```&lt;/p&gt;
&lt;p&gt;All users running an affected release should either upgrade or use one of the
workarounds immediately.&lt;/p&gt;
&lt;p&gt;## Workarounds
Remove these middleware from your application&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2022-30123</guid>
    </item>
    <item>
      <title>certfr-2022-avi-506 — De multiples vulnérabilités ont été découvertes dans Ruby on Rails .
Elles permettent à un attaquant de provoquer une e…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-506</link>
      <description>certfr-2022-avi-506</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-506</guid>
    </item>
    <item>
      <title>EUVD-2026-16418</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-16418</link>
      <description>EUVD-2026-16418</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-16418</guid>
    </item>
    <item>
      <title>fkie_cve-2022-30123</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-30123</link>
      <description>&lt;p&gt;A sequence injection vulnerability exists in Rack &amp;lt;2.0.9.1, &amp;lt;2.1.4.1 and &amp;lt;2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A sequence injection vulnerability exists in Rack &amp;lt;2.0.9.1, &amp;lt;2.1.4.1 and &amp;lt;2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-30123</guid>
    </item>
    <item>
      <title>GHSA-wq4h-7r42-5hrr — Possible shell escape sequence injection vulnerability in Rack</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wq4h-7r42-5hrr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rack&lt;/p&gt;
&lt;p&gt;There is a possible shell escape sequence injection vulnerability in the Lint
and CommonLogger components of Rack.  This vulnerability has been assigned the
CVE identifier CVE-2022-30123.&lt;/p&gt;
&lt;p&gt;Versions Affected:  All.
Not affected:       None
Fixed Versions:     2.0.9.1, 2.1.4.1, 2.2.3.1&lt;/p&gt;
&lt;p&gt;## Impact
Carefully crafted requests can cause shell escape sequences to be written to
the terminal via Rack&amp;#39;s Lint middleware and CommonLogger middleware.  These
escape sequences can be leveraged to possibly execute commands in the victim&amp;#39;s
terminal.&lt;/p&gt;
&lt;p&gt;Impacted applications will have either of these middleware installed, and
vulnerable apps may have something like this:&lt;/p&gt;
&lt;p&gt;```
use Rack::Lint
```&lt;/p&gt;
&lt;p&gt;Or&lt;/p&gt;
&lt;p&gt;```
use Rack::CommonLogger
```&lt;/p&gt;
&lt;p&gt;All users running an affected release should either upgrade or use one of the
workarounds immediately.&lt;/p&gt;
&lt;p&gt;## Workarounds
Remove these middleware from your application&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rack&lt;/p&gt;
&lt;p&gt;There is a possible shell escape sequence injection vulnerability in the Lint
and CommonLogger components of Rack.  This vulnerability has been assigned the
CVE identifier CVE-2022-30123.&lt;/p&gt;
&lt;p&gt;Versions Affected:  All.
Not affected:       None
Fixed Versions:     2.0.9.1, 2.1.4.1, 2.2.3.1&lt;/p&gt;
&lt;p&gt;## Impact
Carefully crafted requests can cause shell escape sequences to be written to
the terminal via Rack&amp;#39;s Lint middleware and CommonLogger middleware.  These
escape sequences can be leveraged to possibly execute commands in the victim&amp;#39;s
terminal.&lt;/p&gt;
&lt;p&gt;Impacted applications will have either of these middleware installed, and
vulnerable apps may have something like this:&lt;/p&gt;
&lt;p&gt;```
use Rack::Lint
```&lt;/p&gt;
&lt;p&gt;Or&lt;/p&gt;
&lt;p&gt;```
use Rack::CommonLogger
```&lt;/p&gt;
&lt;p&gt;All users running an affected release should either upgrade or use one of the
workarounds immediately.&lt;/p&gt;
&lt;p&gt;## Workarounds
Remove these middleware from your application&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wq4h-7r42-5hrr</guid>
    </item>
    <item>
      <title>gsd-2022-30123</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-30123</link>
      <description>gsd-2022-30123</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-30123</guid>
    </item>
    <item>
      <title>OESA-2022-1729 — rubygem-rack security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1729</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rubygem-rack, openEuler:20.03-LTS-SP3: rubygem-rack, openEuler:22.03-LTS: rubygem-rack&lt;/p&gt;
&lt;p&gt;Rack provides a minimal, modular, and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers,  web frameworks, and software in between (the so-called middleware) into  a single method call.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Denial of Service Vulnerability in Rack Multipart Parsing(CVE-2022-30122)&#13;
&#13;
Possible shell escape sequence injection vulnerability in Rack(CVE-2022-30123)&#13;
&#13;
A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;amp;lt; 2.2.3, rack &amp;amp;lt; 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.(CVE-2020-8184)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rubygem-rack, openEuler:20.03-LTS-SP3: rubygem-rack, openEuler:22.03-LTS: rubygem-rack&lt;/p&gt;
&lt;p&gt;Rack provides a minimal, modular, and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers,  web frameworks, and software in between (the so-called middleware) into  a single method call.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Denial of Service Vulnerability in Rack Multipart Parsing(CVE-2022-30122)&#13;
&#13;
Possible shell escape sequence injection vulnerability in Rack(CVE-2022-30123)&#13;
&#13;
A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;amp;lt; 2.2.3, rack &amp;amp;lt; 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.(CVE-2020-8184)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1729</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12119-1 — ruby3.1-rubygem-rack-2.2.3.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12119-1</link>
      <description>&lt;p&gt;ruby3.1-rubygem-rack-2.2.3.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby3.1-rubygem-rack-2.2.3.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12119-1</guid>
    </item>
    <item>
      <title>RHSA-2023:0632 — Red Hat Security Advisory: Red Hat OpenShift (Logging Subsystem) security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:0632</link>
      <description>&lt;p&gt;rubygem-rack: crafted requests can cause shell escape sequences golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rubygem-rack: crafted requests can cause shell escape sequences golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:0632</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:2192-1 — Security update for rubygem-rack</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:2192-1</link>
      <description>&lt;p&gt;Security update for rubygem-rack&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rubygem-rack&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:2192-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-30123</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-30123</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ruby-rack, Ubuntu:Pro:16.04:LTS: ruby-rack, Ubuntu:Pro:18.04:LTS: ruby-rack, Ubuntu:Pro:20.04:LTS: ruby-rack, Ubuntu:22.04:LTS: ruby-rack, Ubuntu:Pro:22.04:LTS: ruby-rack&lt;/p&gt;
&lt;p&gt;A sequence injection vulnerability exists in Rack &amp;lt;2.0.9.1, &amp;lt;2.1.4.1 and &amp;lt;2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ruby-rack, Ubuntu:Pro:16.04:LTS: ruby-rack, Ubuntu:Pro:18.04:LTS: ruby-rack, Ubuntu:Pro:20.04:LTS: ruby-rack, Ubuntu:22.04:LTS: ruby-rack, Ubuntu:Pro:22.04:LTS: ruby-rack&lt;/p&gt;
&lt;p&gt;A sequence injection vulnerability exists in Rack &amp;lt;2.0.9.1, &amp;lt;2.1.4.1 and &amp;lt;2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-30123</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0262 — Ruby: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0262</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby ausnutzen, um einen Denial of Service Angriff durchzuführen, einen Cross-Site-Scripting-Angriff durchzuführen oder beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby ausnutzen, um einen Denial of Service Angriff durchzuführen, einen Cross-Site-Scripting-Angriff durchzuführen oder beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0262</guid>
    </item>
  </channel>
</rss>
