SUSE-SU-2023:3255-1
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 09 Aug 2023, 11:30
Last modified:04 Feb 2026, 03:27
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
09 Aug 2023, 11:30
Published
Vulnerability first disclosed
04 Feb 2026, 03:27
Last Modified
Vulnerability information updated
Description
Security update for rubygem-actionpack-4_2 This update for rubygem-actionpack-4_2 fixes the following issues: - CVE-2023-28362: Fixed XSS via User Supplied Values to redirect_to (bsc#1213312).
Affected Systems
- suse•rubygem-actionpack-4_2&distro=SUSE OpenStack Cloud Crowbar 8
< 4.2.9-7.18.1
- suse•rubygem-actionpack-4_2&distro=SUSE OpenStack Cloud Crowbar 9
< 4.2.9-7.18.1