Skip to content

[deps] bump rexml default gem to 3.3.9#8396

Merged
headius merged 1 commit intojruby:masterfrom
kares:bump-rexml
Oct 30, 2024
Merged

[deps] bump rexml default gem to 3.3.9#8396
headius merged 1 commit intojruby:masterfrom
kares:bump-rexml

Conversation

@kares
Copy link
Member

@kares kares commented Oct 30, 2024

due CVE reports (CVE-2024-49761 REXML ReDoS vulnerability)

Name: rexml
Version: 3.3.8
CVE: CVE-2024-49761
GHSA: GHSA-2rxp-v6pw-ch6m
Criticality: Unknown
URL: https://github.com/ruby/rexml/security/advisories/GHSA-2rxp-v6pw-ch6m
Title: REXML ReDoS vulnerability
Solution: update to '>= 3.3.9'

@kares kares added this to the JRuby 9.4.9.0 milestone Oct 30, 2024
@headius headius merged commit 8c12e3b into jruby:master Oct 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants