SUSE-SU-2017:2716-1

Advisory lineage Upstream: 3 Downstream: 0
Published: 12 Oct 2017, 12:43
Last modified:04 Feb 2026, 02:58

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Oct 2017, 12:43
Published
Vulnerability first disclosed
04 Feb 2026, 02:58
Last Modified
Vulnerability information updated

Description

Security update for the Ruby on Rails stack This update brings version 4.2.9 of the Ruby on Rails stack to provide the latest fixes and improvements from upstream. The following security issues have been fixed by upstream: rubygem-actionpack-4_2 - CVE-2016-2098: Action Pack in Ruby on Rails allowed remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method (bsc#968849). rubygem-activerecord-4_2 - CVE-2016-6317: Action Record did not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allowed remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request (bsc#993313). rubygem-actionview-4_2 - CVE-2016-6316: Cross-site scripting (XSS) vulnerability in Action View might have allowed remote attackers to inject arbitrary web script or HTML via text declared as 'HTML safe' and used as attribute values in tag handlers (bsc#993302). Additionally, the following packages have been updated to version 4.2.9: - rubygem-rails-4_2 - rubygem-railties-4_2 - rubygem-activesupport-4_2 - rubygem-activerecord-4_2 - rubygem-activejob-4_2 - rubygem-actionview-4_2 - rubygem-actionpack-4_2 - rubygem-actionmailer-4_2

Affected Systems

  • suserubygem-actionmailer-4_2&distro=SUSE Enterprise Storage 3

    < 4.2.9-3.3.1

  • suserubygem-actionmailer-4_2&distro=SUSE Enterprise Storage 4

    < 4.2.9-3.3.1

  • suserubygem-actionmailer-4_2&distro=SUSE OpenStack Cloud 6

    < 4.2.9-3.3.1

  • suserubygem-actionmailer-4_2&distro=SUSE OpenStack Cloud 7

    < 4.2.9-3.3.1

  • suserubygem-actionpack-4_2&distro=SUSE Enterprise Storage 3

    < 4.2.9-7.3.1

  • suserubygem-actionpack-4_2&distro=SUSE Enterprise Storage 4

    < 4.2.9-7.3.1

  • suserubygem-actionpack-4_2&distro=SUSE OpenStack Cloud 6

    < 4.2.9-7.3.1

  • suserubygem-actionpack-4_2&distro=SUSE OpenStack Cloud 7

    < 4.2.9-7.3.1

  • suserubygem-actionview-4_2&distro=SUSE Enterprise Storage 3

    < 4.2.9-9.3.1

  • suserubygem-actionview-4_2&distro=SUSE Enterprise Storage 4

    < 4.2.9-9.3.1

  • suserubygem-actionview-4_2&distro=SUSE OpenStack Cloud 6

    < 4.2.9-9.3.1

  • suserubygem-actionview-4_2&distro=SUSE OpenStack Cloud 7

    < 4.2.9-9.3.1

  • suserubygem-activejob-4_2&distro=SUSE Enterprise Storage 3

    < 4.2.9-3.3.1

  • suserubygem-activejob-4_2&distro=SUSE Enterprise Storage 4

    < 4.2.9-3.3.1

  • suserubygem-activejob-4_2&distro=SUSE OpenStack Cloud 6

    < 4.2.9-3.3.1

  • suserubygem-activejob-4_2&distro=SUSE OpenStack Cloud 7

    < 4.2.9-3.3.1

  • suserubygem-activemodel-4_2&distro=SUSE Enterprise Storage 3

    < 4.2.9-6.3.1

  • suserubygem-activemodel-4_2&distro=SUSE Enterprise Storage 4

    < 4.2.9-6.3.1

  • suserubygem-activemodel-4_2&distro=SUSE OpenStack Cloud 6

    < 4.2.9-6.3.1

  • suserubygem-activemodel-4_2&distro=SUSE OpenStack Cloud 7

    < 4.2.9-6.3.1

  • suserubygem-activerecord-4_2&distro=SUSE Enterprise Storage 3

    < 4.2.9-6.3.1

  • suserubygem-activerecord-4_2&distro=SUSE Enterprise Storage 4

    < 4.2.9-6.3.1

  • suserubygem-activerecord-4_2&distro=SUSE OpenStack Cloud 6

    < 4.2.9-6.3.1

  • suserubygem-activerecord-4_2&distro=SUSE OpenStack Cloud 7

    < 4.2.9-6.3.1

  • suserubygem-activesupport-4_2&distro=SUSE Enterprise Storage 3

    < 4.2.9-7.3.1

  • suserubygem-activesupport-4_2&distro=SUSE Enterprise Storage 4

    < 4.2.9-7.3.1

  • suserubygem-activesupport-4_2&distro=SUSE OpenStack Cloud 6

    < 4.2.9-7.3.1

  • suserubygem-activesupport-4_2&distro=SUSE OpenStack Cloud 7

    < 4.2.9-7.3.1

  • suserubygem-rails-4_2&distro=SUSE Enterprise Storage 3

    < 4.2.9-3.3.1

  • suserubygem-rails-4_2&distro=SUSE Enterprise Storage 4

    < 4.2.9-3.3.1

  • suserubygem-rails-4_2&distro=SUSE OpenStack Cloud 6

    < 4.2.9-3.3.1

  • suserubygem-rails-4_2&distro=SUSE OpenStack Cloud 7

    < 4.2.9-3.3.1

  • suserubygem-rails-html-sanitizer&distro=SUSE Enterprise Storage 3

    < 1.0.3-8.3.1

  • suserubygem-rails-html-sanitizer&distro=SUSE Enterprise Storage 4

    < 1.0.3-8.3.1

  • suserubygem-rails-html-sanitizer&distro=SUSE OpenStack Cloud 6

    < 1.0.3-8.3.1

  • suserubygem-rails-html-sanitizer&distro=SUSE OpenStack Cloud 7

    < 1.0.3-8.3.1

  • suserubygem-railties-4_2&distro=SUSE Enterprise Storage 3

    < 4.2.9-3.3.1

  • suserubygem-railties-4_2&distro=SUSE Enterprise Storage 4

    < 4.2.9-3.3.1

  • suserubygem-railties-4_2&distro=SUSE OpenStack Cloud 6

    < 4.2.9-3.3.1

  • suserubygem-railties-4_2&distro=SUSE OpenStack Cloud 7

    < 4.2.9-3.3.1

References (8)