Project

General

Profile

Actions

Defect #38539

closed

Update Nokogiri to 1.15.2 in 5.0-stable and 4.2-stable

Added by A Fora 12 months ago. Updated 11 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Security
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Resolution:
Fixed
Affected version:

Description

Here's the details:

Name: activesupport
Version: 6.1.7.2
CVE: CVE-2023-28120
GHSA: GHSA-pj73-v5mw-pm9j
Criticality: Unknown
URL: https://discuss.rubyonrails.org/t/cve-2023-28120-possible-xss-security-vulnerability-in-safebuffer-bytesplice/82469
Title: Possible XSS Security Vulnerability in SafeBuffer#bytesplice
Solution: upgrade to '~> 6.1.7, >= 6.1.7.3', '>= 7.0.4.3'

Name: nokogiri
Version: 1.13.10
GHSA: GHSA-pxvg-2qj5-37jq
Criticality: Unknown
URL: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-pxvg-2qj5-37jq
Title: Update packaged libxml2 to v2.10.4 to resolve multiple CVEs
Solution: upgrade to '>= 1.14.3'

Vulnerabilities found!

Related issues

Related to Redmine - Patch #38181: Update Nokogiri to 1.15.2ClosedGo MAEDA

Actions
Related to Redmine - Patch #38374: Update Rails to 6.1.7.6ClosedGo MAEDA

Actions
Actions

Also available in: Atom PDF