MGASA-2026-0075 - Updated ruby-rack packages fix security vulnerabilities. MGASA-2026-0075 - Updated ruby-rack packages fix security vulnerabilities Publication date: 31 Mar 2026 URL: https://advisories.mageia.org/MGASA-2026-0075.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-22860, CVE-2026-25500 Description: Rack has a Directory Traversal via Rack:Directory. (CVE-2026-22860) Rack's Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href. (CVE-2026-25500) References: - https://bugs.mageia.org/show_bug.cgi?id=35285 - https://lists.debian.org/debian-security-announce/2026/msg00089.html - https://www.cve.org/CVERecord?id=CVE-2026-22860 - https://www.cve.org/CVERecord?id=CVE-2026-25500 SRPMS: - 9/core/ruby-rack-2.2.22-1.mga9 . Updated ruby-rack packages for Mageia fix critical security flaws, including directory traversal and stored XSS issues.. Mageia Ruby Rack Security Patch 2026. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for grafana ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2715-1 Rating: moderate References: #1174583 Cross-References: CVE-2020-11110 Affected Products: SUSE Enterprise Storage 5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for grafana fixes the following issues: - CVE-2020-11110: Fixed a stored XSS in dashboard snapshot original dashboard link (bsc#1174583). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2020-2715=1 Package List: - SUSE Enterprise Storage 5 (aarch64 x86_64): grafana-4.6.5-3.13.1 grafana-debuginfo-4.6.5-3.13.1 grafana-debugsource-4.6.5-3.13.1 References: https://www.suse.com/security/cve/CVE-2020-11110.html https://bugzilla.suse.com/1174583 _______________________________________________ sle-security-updates mailing list
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for nextcloud ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:3999-1 Rating: moderate References: #1114817 Cross-References: CVE-2018-3780 Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for nextcloud fixes security issues and bugs. Security issues fixed: - CVE-2018-3780: Stored XSS in autocomplete suggestions for file comments (boo#1114817) This update also contains all bug fixes and improvements in the 13.0.8 version, including: - Password expiration time changed from 12h to 7d - Bug fixes to the OAuth brute force protection - Various other bug fixes and improvements Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Package Hub for SUSE Linux Enterprise 12: zypper in -t patch openSUSE-2018-1487=1 Package List: - SUSE Package Hub for SUSE Linux Enterprise 12 (noarch): nextcloud-13.0.8-8.1 References: https://www.suse.com/security/cve/CVE-2018-3780.html https://bugzilla.suse.com/1114817 -- . openSUSE releases a patch addressing a medium-level security flaw in Nextcloud: an instance of stored XSS found in autocomplete features.. openSUSE Security Update, Nextcloud Vulnerability Fix, XSS Protection. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.