# ruby3.4-rubygem-loofah-2.23.1-1.3 on GA media Announcement ID: openSUSE-SU-2025:15120-1 Rating: moderate Cross-References: * CVE-2018-16468 * CVE-2018-8048 * CVE-2019-15587 * CVE-2022-23514 * CVE-2022-23515 * CVE-2022-23516 CVSS scores: * CVE-2018-16468 ( SUSE ): 6.4 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L * CVE-2018-8048 ( SUSE ): 5.4 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2019-15587 ( SUSE ): 6.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2022-23514 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-23515 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2022-23516 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Tumbleweed An update that solves 6 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the ruby3.4-rubygem-loofah-2.23.1-1.3 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * ruby3.4-rubygem-loofah 2.23.1-1.3 ## References: * https://www.suse.com/security/cve/CVE-2018-16468.html * https://www.suse.com/security/cve/CVE-2018-8048.html * https://www.suse.com/security/cve/CVE-2019-15587.html * https://www.suse.com/security/cve/CVE-2022-23514.html * https://www.suse.com/security/cve/CVE-2022-23515.html * https://www.suse.com/security/cve/CVE-2022-23516.html