diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 4b706f3cbea9..a7e3ba6b9201 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,43 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + Rails -- Action View vulnerabilities + + + rubygem-actionview4 + 4.2.11.1 + + + rubygem-actionview50 + 5.0.7.2 + + + rubygem-actionview5 + 5.1.6.2 + + + + +

Ruby on Rails blog:

+
+

Rails 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1, and 6.0.0.beta3 have been released! These contain the following important security fixes. It is recommended that users upgrade as soon as possible:

+

CVE-2019-5418 File Content Disclosure in Action View

+

CVE-2019-5419 Denial of Service Vulnerability in Action View

+
+ +
+ + https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/ + CVE-2019-5418 + CVE-2019-5419 + + + 2019-03-13 + 2019-03-18 + +
+ PuTTY -- security fixes in new release