Skip to content

Address security vulnerability in rubyzip dependency - #602

Open
waterjump wants to merge 1 commit into
randym:masterfrom
mes:master
Open

Address security vulnerability in rubyzip dependency#602
waterjump wants to merge 1 commit into
randym:masterfrom
mes:master

Conversation

@waterjump

Copy link
Copy Markdown

The rubyzip gem version 1.2.1 contains a security vulnerability allowing
absolute path traversal. More details can be found here:

rubyzip/rubyzip#369

This change addresses the issue by specifying a rubyzip version greater
than or equal to 1.2.2.

Solves issue #599

The rubyzip gem version 1.2.1 contains a security vulnerability allowing
absolute path traversal.  More details can be found here:

rubyzip/rubyzip#369

This change addresses the issue by specifying a rubyzip version greater
than or equal to 1.2.2.

Solves issue randym#599
@why-el

why-el commented Sep 11, 2018

Copy link
Copy Markdown

@waterjump any chance you release a new version with this change? It's a pretty serious one.

@waterjump

Copy link
Copy Markdown
Author

@why-el Seems like bumping it to 3.0.1 would be a good idea. I'd like to confirm with the gem owner because people tend to do this differently from time to time and there's nothing in the README about contribution guidelines etc.

@why-el

why-el commented Sep 11, 2018

Copy link
Copy Markdown

Ok, thanks the prompt response. Up to @randym then.

@noniq

noniq commented Sep 11, 2018

Copy link
Copy Markdown
Collaborator

See also #536

@sullyvannunes

Copy link
Copy Markdown

I am facing this same problem with rubyzip version.
is there any update about this issue?

@courtsimas

Copy link
Copy Markdown

Ping. What's the latest?

@waterjump

Copy link
Copy Markdown
Author

@courtsimas We are waiting on feedback from @randym regarding version bump.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants