|
|
|
|
|
by zwp
1477 days ago
|
|
Rexml has been gemified. Shale's gemspec doesn't require a specific version of rexml and rexml<3.2.5 is vulnerable to CVE-2021-28965. I just checked Ubuntu 20.04 LTS and got Ruby 2.7 with rexml 3.2.3 by default so this seems like a realistic concern and it would be safer if shale required a minimum rexml version. See http://www.ruby-lang.org/en/news/2021/04/05/xml-round-trip-v... |
|