Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nokogiri-1.15.3 in td-agent v4.5.3 has vulnerability(CVE-2019-18425) #628

Closed
mvpotdar opened this issue Mar 5, 2024 · 1 comment
Closed

Comments

@mvpotdar
Copy link

mvpotdar commented Mar 5, 2024

Hi,

I noticed that the Gemfile from td-agent latest version v4.5.3 specifies nokogiri-1.15.3, which contains a vulnerability (CVE-2019-18425).

I'm wondering if there are any plans to address this issue in an upcoming release.

@ashie
Copy link
Member

ashie commented Mar 6, 2024

which contains a vulnerability (GHSA-wfcx-xxhx-657g).

It doesn't seem concerned with nokogiri.

td-agent v4 is already EOL: https://www.fluentd.org/blog/schedule-for-td-agent-4-eol
If you need to keep using v4 and to update gems, please upgrade them by yourself.

e.g.)

> td-agent-gem install nokogiri -v 1.15.5

@ashie ashie closed this as completed Mar 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants