Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

🚨 [security] Update nokogiri: 1.8.1 β†’ 1.8.2 (patch) #2413

Merged
merged 1 commit into from Jan 31, 2018

Conversation

depfu[bot]
Copy link
Contributor

@depfu depfu bot commented Jan 31, 2018


🚨 Your version of nokogiri has known security vulnerabilities 🚨

Advisory: CVE-2017-15412
Disclosed: January 29, 2018
URL: https://github.com/sparklemotion/nokogiri/issues/1714

libxml2 could be made to crash or run arbitrary code if it opened a specially crafted file

The update of vendored libxml2 from 2.9.5 to 2.9.7 addresses at least one published vulnerability, CVE-2017-15412. If you're using your distro's system libraries, rather than Nokogiri's vendored libraries, there's no security need to upgrade at this time.

Details: It was discovered that libxml2 incorrecty handled certain files. An attacker could use this issue with specially constructed XML data to cause libxml2 to consume resources, leading to a denial of service.


🚨 We recommend to merge and deploy this update as soon as possible! 🚨

We've updated a dependency and here is what you need to know:

gem name version specification old version new version
nokogiri indirect dependency 1.8.1 1.8.2

You should probably take a good look at the info here and the test results before merging this pull request, of course.

What changed?

↗️ nokogiri (indirect, 1.8.1 β†’ 1.8.2) Β· Repo Β· Changelog

Commits

See the full diff on Github. The new version differs by 29 commits:


Depfu will automatically keep this PR conflict-free, as long as you don't add any commits yourself. You can also trigger a rebase manually by commenting with @depfu rebase.

Depfu Status

@depfu depfu bot added the Depfu label Jan 31, 2018
@voodoorai2000 voodoorai2000 merged commit 48f084d into master Jan 31, 2018
@depfu depfu bot deleted the depfu/update/nokogiri-1.8.2 branch January 31, 2018 18:21
clairezed pushed a commit to CDJ11/CDJ that referenced this pull request Jun 26, 2018
…giri-1.8.2

🚨 [security] Update nokogiri: 1.8.1 β†’ 1.8.2 (patch)
@javierm javierm added dependencies Pull requests that updates a dependency and removed Depfu labels Sep 20, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that updates a dependency
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants