-
Notifications
You must be signed in to change notification settings - Fork 734
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
loofah 2.10.0 release flagged as CVE-2018-8048 (loofah < 2.2.1) #1603
Comments
|
Gem::Version.new("2.10") < Gem::Version.new("2.2.1") # => false |
presidentbeef
added a commit
that referenced
this issue
Jun 7, 2021
presidentbeef
added a commit
that referenced
this issue
Jun 7, 2021
presidentbeef
added a commit
that referenced
this issue
Jun 8, 2021
maatinito
added a commit
to govpf/mes-demarches
that referenced
this issue
Sep 15, 2021
Repository owner
locked and limited conversation to collaborators
Jan 30, 2022
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Background
Brakeman version: 5.0.1
Rails version: 6.1.3.2
Ruby version: 3.0.1
False Positive
Full warning from Brakeman:
Why might this be a false positive?
loofah 2.10.0 (released today) is later than 2.2.1, but the version comparison seems to be parsing it as being earlier than 2.2.1.
The text was updated successfully, but these errors were encountered: