rpm package
opensuse/rubygem-actionmailer-6.0&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/rubygem-actionmailer-6.0&distro=openSUSE%20Tumbleweed
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-8264 | — | < 6.0.4.4-1.1 | 6.0.4.4-1.1 | Jan 6, 2021 | In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local applic | ||
| CVE-2019-5418 | — | KEV | < 6.0.4.4-1.1 | 6.0.4.4-1.1 | Mar 27, 2019 | There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed. |
- CVE-2020-8264Jan 6, 2021affected < 6.0.4.4-1.1fixed 6.0.4.4-1.1
In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local applic
- affected < 6.0.4.4-1.1fixed 6.0.4.4-1.1
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.