Actions
Defect #38539
closedUpdate Nokogiri to 1.15.2 in 5.0-stable and 4.2-stable
Start date:
Due date:
% Done:
0%
Estimated time:
Resolution:
Fixed
Affected version:
Description
Here's the details:
Name: activesupport
Version: 6.1.7.2
CVE: CVE-2023-28120
GHSA: GHSA-pj73-v5mw-pm9j
Criticality: Unknown
URL: https://discuss.rubyonrails.org/t/cve-2023-28120-possible-xss-security-vulnerability-in-safebuffer-bytesplice/82469
Title: Possible XSS Security Vulnerability in SafeBuffer#bytesplice
Solution: upgrade to '~> 6.1.7, >= 6.1.7.3', '>= 7.0.4.3'
Name: nokogiri
Version: 1.13.10
GHSA: GHSA-pxvg-2qj5-37jq
Criticality: Unknown
URL: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-pxvg-2qj5-37jq
Title: Update packaged libxml2 to v2.10.4 to resolve multiple CVEs
Solution: upgrade to '>= 1.14.3'
Vulnerabilities found!
Related issues
Updated by Holger Just almost 2 years ago
- Related to Patch #38181: Update Nokogiri to 1.15.2 added
Updated by Go MAEDA almost 2 years ago
- Subject changed from Ruby vulnerabilities reported for v.5.0.5 (I cant select 5.0.5 from versions list) to Update Nokogiri to 1.15.2
- Target version set to 4.2.11
Updated by Go MAEDA almost 2 years ago
- Subject changed from Update Nokogiri to 1.15.2 to Update Nokogiri to 1.15.2 in 5.0-stable and 4.2-stable
- Status changed from Confirmed to Closed
- Resolution set to Fixed
Actions