Skip to content
This repository has been archived by the owner on Jul 21, 2020. It is now read-only.

Security update for compromised gems. #130

Merged
merged 1 commit into from
Oct 22, 2018
Merged

Security update for compromised gems. #130

merged 1 commit into from
Oct 22, 2018

Commits on Oct 19, 2018

  1. Security update for compromised gems.

    Name: nokogiri
    Version: 1.8.2
    Advisory: CVE-2018-14404
    Criticality: Unknown
    URL: sparklemotion/nokogiri#1785
    Title: Nokogiri gem, via libxml2, is affected by multiple vulnerabilities
    
    Name: nokogiri
    Version: 1.8.2
    Advisory: CVE-2018-8048
    Criticality: Unknown
    URL: sparklemotion/nokogiri#1746
    Title: Revert libxml2 behavior in Nokogiri gem that could cause XSS
    
    Name: sprockets
    Version: 2.12.4
    Advisory: CVE-2018-3760
    Criticality: Unknown
    URL: https://groups.google.com/forum/#!topic/ruby-security-ann/2S9Pwz2i16k
    Title: Path Traversal in Sprockets
    rimenes committed Oct 19, 2018
    Configuration menu
    Copy the full SHA
    88ee6da View commit details
    Browse the repository at this point in the history