Skip to content

Status for MRI-related security issues? #5126

@thbar

Description

@thbar

I'm maintaining Ruby installations for a client on a regular basis (including both MRI & JRuby on various servers).

MRI got multiple releases to cover multiple CVEs:

Before that, MRI got other fixes recently:

I wondered what the situation is for JRuby with regard to the related CVEs.

The JRuby security page doesn't mention recent CVEs, and the news page hasn't had one for a while if I'm not mistaken.

Does this means that JRuby is unaffected (e.g. if it uses different, underlying JVM components rather than pure Ruby code), or that the evaluation hasn't necessarily been conducted so situation is unknown?

I don't know if opening an issue is the way to go for this, but I thought it is worth clarifying, so this could start a discussion!

Thanks for your work on JRuby.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions