-
-
Notifications
You must be signed in to change notification settings - Fork 942
Closed
Milestone
Description
jruby-complete 9.3.8.0 embeds a version of bundler at ./META-INF/jruby.home/lib/ruby/gems/shared/gems/bundler-2.2.29/ that is subject to CVE-2021-43809.
In
bundlerversions before 2.2.33, when working with untrusted and apparently harmlessGemfile's, it is not expected that they lead to execution of external code, unless that's explicit in the ruby code inside theGemfileitself. ...
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels