Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Translate CVE-2023-28755 (ko) #3007

Merged
merged 4 commits into from
Apr 3, 2023
Merged

Translate CVE-2023-28755 (ko) #3007

merged 4 commits into from
Apr 3, 2023

Conversation

marocchino
Copy link
Member

@marocchino marocchino commented Mar 28, 2023

@marocchino marocchino requested a review from a team as a code owner March 28, 2023 03:24

URI 구성 요소에서 ReDoS 문제가 발견되었습니다. URI 구문 분석기가 특정 문자가 포함된 유효하지 않은 URL을 잘못 처리합니다. 이로 인해 URI 객체에 대한 문자열 구문 분석 실행 시간이 증가합니다.

`uri` gem의 0.10.1, 0.10.2, 0.11.0, 0.12.0 및 모든 0.10.0 이하 버전이 이 취약점에 취약합니다.
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

isn't this typo? I think 0.10.2 is patched version.

Copy link
Member Author

@marocchino marocchino Mar 28, 2023

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I made another pr for en. #3008

@yous
Copy link
Member

yous commented Mar 28, 2023

Ref #3006.

@marocchino marocchino changed the title Translate CVE-2023-28755 (KO) Translate CVE-2023-28755 (ko) Mar 28, 2023
@yous
Copy link
Member

yous commented Mar 30, 2023

Let's wait for #3009.

@yous
Copy link
Member

yous commented Apr 1, 2023

Let's wait for #3009.

Now we can apply the update.

Co-authored-by: Chayoung You <yousbe@gmail.com>
@marocchino marocchino merged commit 1c052b8 into ruby:master Apr 3, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

2 participants