An update that solves one vulnerability can now be installed.. # ruby4.0-rubygem-actionmailer-8.0-8.0.3-1.3 on GA media Announcement ID: openSUSE-SU-2026:10337-1 Rating: moderate Cross-References: * CVE-2024-54133 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the ruby4.0-rubygem-actionmailer-8.0-8.0.3-1.3 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * ruby4.0-rubygem-actionmailer-8.0 8.0.3-1.3 ## References: * https://www.suse.com/security/cve/CVE-2024-54133.html . An openSUSE update for ruby4.0-rubygem-actionmailer resolves a moderate security issue impacting Tumbleweed.. openSUSE actionmailer patch moderate CVE-2024-54133. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # ruby3.4-rubygem-actionmailer-7.0-7.0.8.6-1.3 on GA media Announcement ID: openSUSE-SU-2025:15109-1 Rating: moderate Cross-References: * CVE-2024-47889 CVSS scores: * CVE-2024-47889 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the ruby3.4-rubygem-actionmailer-7.0-7.0.8.6-1.3 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * ruby3.4-rubygem-actionmailer-7.0 7.0.8.6-1.3 ## References: * https://www.suse.com/security/cve/CVE-2024-47889.html . Tackling intermediate security vulnerabilities within Ruby 3.4 ActionMailer on openSUSE Tumbleweed. Perform updates immediately!. openSUSE ruby security update ActionMailer moderate. . LinuxSecurity.com Team
Update to Ruby on Rails 7.0.4.3. https://rubyonrails.org/2023/3/13/Rails-7-0-4-3-and-6-1-7-3-have-been-released. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-7002afbbb8 2023-04-05 01:34:43.146270 --------------------------------------------------------------------------------Name : rubygem-actionmailer Product : Fedora 37 Version : 7.0.4.3 Release : 1.fc37 URL : https://rubyonrails.org Summary : Email composition and delivery framework (part of Rails) Description : Email on Rails. Compose, deliver, and test emails using the familiar controller/view pattern. First-class support for multipart email and attachments. --------------------------------------------------------------------------------Update Information: Update to Ruby on Rails 7.0.4.3. https://rubyonrails.org/2023/3/13/Rails-7-0-4-3-and-6-1-7-3-have-been-released --------------------------------------------------------------------------------ChangeLog: * Tue Mar 14 2023 Pavel Valena - 1:7.0.4.3-1 - Update to actionmailer 7.0.4.3. --------------------------------------------------------------------------------References: [ 1 ] Bug #2179637 - CVE-2023-28120 rubygem-activesupport: Possible XSS in SafeBuffer#bytesplice https://bugzilla.redhat.com/show_bug.cgi?id=2179637 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-7002afbbb8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Upgrade to Ruby on Rails 6.0.3.3. Fixes CVEs: #1877568 #1831529 #1852381. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-4dd34860a3 2020-10-05 00:15:05.246453 --------------------------------------------------------------------------------Name : rubygem-actionmailer Product : Fedora 33 Version : 6.0.3.3 Release : 1.fc33 URL : https://rubyonrails.org Summary : Email composition and delivery framework (part of Rails) Description : Email on Rails. Compose, deliver, and test emails using the familiar controller/view pattern. First-class support for multipart email and attachments. --------------------------------------------------------------------------------Update Information: Upgrade to Ruby on Rails 6.0.3.3. Fixes CVEs: #1877568 #1831529 #1852381 --------------------------------------------------------------------------------ChangeLog: * Tue Sep 22 2020 Pavel Valena - 1:6.0.3.3-1 - Update to actionmailer 6.0.3.3. Resolves: rhbz#1877505 --------------------------------------------------------------------------------References: [ 1 ] Bug #1831529 - CVE-2020-5267 rubygem-actionview: views that use the `j` or `escape_javascript` methods are susceptible to XSS attacks [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1831529 [ 2 ] Bug #1852381 - CVE-2020-8185 rubygem-rails: untrusted users able to run pending migrations in production [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1852381 [ 3 ] Bug #1877568 - CVE-2020-15169 rubygem-actionview: rubygem-activeview: Cross-site scripting in translation helpers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1877568 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-4dd34860a3' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update Ruby on Rails to 5.2.3. Fixes CVE-2019-5418 CVE-2019-5419 CVE-2019-5420.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-1cfe24db5c 2019-05-10 00:46:38.157347 --------------------------------------------------------------------------------Name : rubygem-actionmailer Product : Fedora 30 Version : 5.2.3 Release : 1.fc30 URL : https://rubyonrails.org/ Summary : Email composition, delivery, and receiving framework (part of Rails) Description : Email on Rails. Compose, deliver, receive, and test emails using the familiar controller/view pattern. First-class support for multipart email and attachments. --------------------------------------------------------------------------------Update Information: Update Ruby on Rails to 5.2.3. Fixes CVE-2019-5418 CVE-2019-5419 CVE-2019-5420. --------------------------------------------------------------------------------ChangeLog: * Thu Mar 28 2019 Pavel Valena - 1:5.2.3-1 - Update to Action Mailer 5.2.3. * Thu Mar 14 2019 Pavel Valena - 1:5.2.2.1-1 - Update to Action Mailer 5.2.2.1. --------------------------------------------------------------------------------References: [ 1 ] Bug #1689161 - CVE-2019-5418 CVE-2019-5419 rubygem-actionview: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1689161 [ 2 ] Bug #1689155 - CVE-2019-5420 rubygem-rails: Weak secret token leading to possible code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1689155 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-1cfe24db5c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys usedby the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.