Skip to content

Updated gems deemed unsecure by CVE or GHSA violations - #242

Open
dahogenelst wants to merge 1 commit into
locomotivecms:masterfrom
dahogenelst:pr/cve-violations
Open

Updated gems deemed unsecure by CVE or GHSA violations#242
dahogenelst wants to merge 1 commit into
locomotivecms:masterfrom
dahogenelst:pr/cve-violations

Conversation

@dahogenelst

Copy link
Copy Markdown
Contributor

Name: net-imap
Version: 0.4.16
CVE: CVE-2025-25186
GHSA: GHSA-7fc5-f82f-cx69
Criticality: Medium
URL: GHSA-7fc5-f82f-cx69
Title: Possible DoS by memory exhaustion in net-imap
Solution: update to '> 0.3.8', '> 0.4.19', '>= 0.5.6'

Name: nokogiri
Version: 1.16.7
GHSA: GHSA-mrxw-mxhj-p664
Criticality: High
URL: GHSA-mrxw-mxhj-p664
Title: Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
Solution: update to '>= 1.18.4'

Name: nokogiri
Version: 1.16.7
GHSA: GHSA-vvfq-8hwr-qm4m
Criticality: Unknown
URL: GHSA-vvfq-8hwr-qm4m
Title: Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171
Solution: update to '>= 1.18.3'

Name: nokogiri
Version: 1.16.7
GHSA: GHSA-mrxw-mxhj-p664
Criticality: High
URL: GHSA-mrxw-mxhj-p664
Title: Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
Solution: update to '>= 1.18.4'

Name: nokogiri
Version: 1.16.7
GHSA: GHSA-vvfq-8hwr-qm4m
Criticality: Unknown
URL: GHSA-vvfq-8hwr-qm4m
Title: Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171
Solution: update to '>= 1.18.3'

Name: rack
Version: 3.1.7
CVE: CVE-2025-25184
GHSA: GHSA-7g2v-jj9q-g3rg
Criticality: Unknown
URL: GHSA-7g2v-jj9q-g3rg
Title: Possible Log Injection in Rack::CommonLogger
Solution: update to '> 2.2.11', '> 3.0.12', '>= 3.1.10'

Name: rack
Version: 3.1.7
CVE: CVE-2025-27111
GHSA: GHSA-8cgq-6mh2-7j6v
Criticality: Unknown
URL: GHSA-8cgq-6mh2-7j6v
Title: Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection
Solution: update to '> 2.2.12', '> 3.0.13', '>= 3.1.11'

Name: rack
Version: 3.1.7
CVE: CVE-2025-27610
GHSA: GHSA-7wqh-767x-r66v
Criticality: High
URL: GHSA-7wqh-767x-r66v
Title: Local File Inclusion in Rack::Static
Solution: update to '> 2.2.13', '> 3.0.14', '>= 3.1.12'

Name: rexml
Version: 3.3.8
CVE: CVE-2024-49761
GHSA: GHSA-2rxp-v6pw-ch6m
Criticality: High
URL: GHSA-2rxp-v6pw-ch6m
Title: REXML ReDoS vulnerability
Solution: update to '>= 3.3.9'

Name: net-imap
Version: 0.4.16
CVE: CVE-2025-25186
GHSA: GHSA-7fc5-f82f-cx69
Criticality: Medium
URL: GHSA-7fc5-f82f-cx69
Title: Possible DoS by memory exhaustion in net-imap
Solution: update to '~> 0.3.8', '~> 0.4.19', '>= 0.5.6'

Name: nokogiri
Version: 1.16.7
GHSA: GHSA-mrxw-mxhj-p664
Criticality: High
URL: GHSA-mrxw-mxhj-p664
Title: Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
Solution: update to '>= 1.18.4'

Name: nokogiri
Version: 1.16.7
GHSA: GHSA-vvfq-8hwr-qm4m
Criticality: Unknown
URL: GHSA-vvfq-8hwr-qm4m
Title: Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171
Solution: update to '>= 1.18.3'

Name: nokogiri
Version: 1.16.7
GHSA: GHSA-mrxw-mxhj-p664
Criticality: High
URL: GHSA-mrxw-mxhj-p664
Title: Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
Solution: update to '>= 1.18.4'

Name: nokogiri
Version: 1.16.7
GHSA: GHSA-vvfq-8hwr-qm4m
Criticality: Unknown
URL: GHSA-vvfq-8hwr-qm4m
Title: Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171
Solution: update to '>= 1.18.3'

Name: rack
Version: 3.1.7
CVE: CVE-2025-25184
GHSA: GHSA-7g2v-jj9q-g3rg
Criticality: Unknown
URL: GHSA-7g2v-jj9q-g3rg
Title: Possible Log Injection in Rack::CommonLogger
Solution: update to '~> 2.2.11', '~> 3.0.12', '>= 3.1.10'

Name: rack
Version: 3.1.7
CVE: CVE-2025-27111
GHSA: GHSA-8cgq-6mh2-7j6v
Criticality: Unknown
URL: GHSA-8cgq-6mh2-7j6v
Title: Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection
Solution: update to '~> 2.2.12', '~> 3.0.13', '>= 3.1.11'

Name: rack
Version: 3.1.7
CVE: CVE-2025-27610
GHSA: GHSA-7wqh-767x-r66v
Criticality: High
URL: GHSA-7wqh-767x-r66v
Title: Local File Inclusion in Rack::Static
Solution: update to '~> 2.2.13', '~> 3.0.14', '>= 3.1.12'

Name: rexml
Version: 3.3.8
CVE: CVE-2024-49761
GHSA: GHSA-2rxp-v6pw-ch6m
Criticality: High
URL: GHSA-2rxp-v6pw-ch6m
Title: REXML ReDoS vulnerability
Solution: update to '>= 3.3.9'
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants