SUSE-SU-2023:3255-1

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 09 Aug 2023, 11:30
Last modified:04 Feb 2026, 03:27

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Aug 2023, 11:30
Published
Vulnerability first disclosed
04 Feb 2026, 03:27
Last Modified
Vulnerability information updated

Description

Security update for rubygem-actionpack-4_2 This update for rubygem-actionpack-4_2 fixes the following issues: - CVE-2023-28362: Fixed XSS via User Supplied Values to redirect_to (bsc#1213312).

Affected Systems

  • suserubygem-actionpack-4_2&distro=SUSE OpenStack Cloud Crowbar 8

    < 4.2.9-7.18.1

  • suserubygem-actionpack-4_2&distro=SUSE OpenStack Cloud Crowbar 9

    < 4.2.9-7.18.1

References (3)