Updated gems deemed unsecure by CVE or GHSA violations - #242
Open
dahogenelst wants to merge 1 commit into
Open
Conversation
Name: net-imap Version: 0.4.16 CVE: CVE-2025-25186 GHSA: GHSA-7fc5-f82f-cx69 Criticality: Medium URL: GHSA-7fc5-f82f-cx69 Title: Possible DoS by memory exhaustion in net-imap Solution: update to '~> 0.3.8', '~> 0.4.19', '>= 0.5.6' Name: nokogiri Version: 1.16.7 GHSA: GHSA-mrxw-mxhj-p664 Criticality: High URL: GHSA-mrxw-mxhj-p664 Title: Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs Solution: update to '>= 1.18.4' Name: nokogiri Version: 1.16.7 GHSA: GHSA-vvfq-8hwr-qm4m Criticality: Unknown URL: GHSA-vvfq-8hwr-qm4m Title: Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171 Solution: update to '>= 1.18.3' Name: nokogiri Version: 1.16.7 GHSA: GHSA-mrxw-mxhj-p664 Criticality: High URL: GHSA-mrxw-mxhj-p664 Title: Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs Solution: update to '>= 1.18.4' Name: nokogiri Version: 1.16.7 GHSA: GHSA-vvfq-8hwr-qm4m Criticality: Unknown URL: GHSA-vvfq-8hwr-qm4m Title: Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171 Solution: update to '>= 1.18.3' Name: rack Version: 3.1.7 CVE: CVE-2025-25184 GHSA: GHSA-7g2v-jj9q-g3rg Criticality: Unknown URL: GHSA-7g2v-jj9q-g3rg Title: Possible Log Injection in Rack::CommonLogger Solution: update to '~> 2.2.11', '~> 3.0.12', '>= 3.1.10' Name: rack Version: 3.1.7 CVE: CVE-2025-27111 GHSA: GHSA-8cgq-6mh2-7j6v Criticality: Unknown URL: GHSA-8cgq-6mh2-7j6v Title: Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection Solution: update to '~> 2.2.12', '~> 3.0.13', '>= 3.1.11' Name: rack Version: 3.1.7 CVE: CVE-2025-27610 GHSA: GHSA-7wqh-767x-r66v Criticality: High URL: GHSA-7wqh-767x-r66v Title: Local File Inclusion in Rack::Static Solution: update to '~> 2.2.13', '~> 3.0.14', '>= 3.1.12' Name: rexml Version: 3.3.8 CVE: CVE-2024-49761 GHSA: GHSA-2rxp-v6pw-ch6m Criticality: High URL: GHSA-2rxp-v6pw-ch6m Title: REXML ReDoS vulnerability Solution: update to '>= 3.3.9'
did
approved these changes
Apr 23, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Name: net-imap
Version: 0.4.16
CVE: CVE-2025-25186
GHSA: GHSA-7fc5-f82f-cx69
Criticality: Medium
URL: GHSA-7fc5-f82f-cx69
Title: Possible DoS by memory exhaustion in net-imap
Solution: update to '
> 0.3.8', '> 0.4.19', '>= 0.5.6'Name: nokogiri
Version: 1.16.7
GHSA: GHSA-mrxw-mxhj-p664
Criticality: High
URL: GHSA-mrxw-mxhj-p664
Title: Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
Solution: update to '>= 1.18.4'
Name: nokogiri
Version: 1.16.7
GHSA: GHSA-vvfq-8hwr-qm4m
Criticality: Unknown
URL: GHSA-vvfq-8hwr-qm4m
Title: Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171
Solution: update to '>= 1.18.3'
Name: nokogiri
Version: 1.16.7
GHSA: GHSA-mrxw-mxhj-p664
Criticality: High
URL: GHSA-mrxw-mxhj-p664
Title: Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
Solution: update to '>= 1.18.4'
Name: nokogiri
Version: 1.16.7
GHSA: GHSA-vvfq-8hwr-qm4m
Criticality: Unknown
URL: GHSA-vvfq-8hwr-qm4m
Title: Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171
Solution: update to '>= 1.18.3'
Name: rack
Version: 3.1.7
CVE: CVE-2025-25184
GHSA: GHSA-7g2v-jj9q-g3rg
Criticality: Unknown
URL: GHSA-7g2v-jj9q-g3rg
Title: Possible Log Injection in Rack::CommonLogger
Solution: update to '
> 2.2.11', '> 3.0.12', '>= 3.1.10'Name: rack
Version: 3.1.7
CVE: CVE-2025-27111
GHSA: GHSA-8cgq-6mh2-7j6v
Criticality: Unknown
URL: GHSA-8cgq-6mh2-7j6v
Title: Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection
Solution: update to '
> 2.2.12', '> 3.0.13', '>= 3.1.11'Name: rack
Version: 3.1.7
CVE: CVE-2025-27610
GHSA: GHSA-7wqh-767x-r66v
Criticality: High
URL: GHSA-7wqh-767x-r66v
Title: Local File Inclusion in Rack::Static
Solution: update to '
> 2.2.13', '> 3.0.14', '>= 3.1.12'Name: rexml
Version: 3.3.8
CVE: CVE-2024-49761
GHSA: GHSA-2rxp-v6pw-ch6m
Criticality: High
URL: GHSA-2rxp-v6pw-ch6m
Title: REXML ReDoS vulnerability
Solution: update to '>= 3.3.9'