Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Updates #849

Open
wants to merge 5 commits into
base: master
Choose a base branch
from
Open

Security Updates #849

wants to merge 5 commits into from

Commits on Sep 17, 2020

  1. Update chartkick to 3.4.0

    Name: chartkick
    Version: 3.3.0
    Advisory: CVE-2020-16254
    Criticality: Unknown
    URL: ankane/chartkick#546
    Title: CSS injection with width and height options
    Solution: upgrade to >= 3.4.0
    Alexy Mikhailichenko committed Sep 17, 2020
    Configuration menu
    Copy the full SHA
    939eb18 View commit details
    Browse the repository at this point in the history
  2. Update geocoder to 1.6.3

    Name: geocoder
    Version: 1.5.1
    Advisory: CVE-2020-7981
    Criticality: High
    URL: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7981
    Title: Geocoder gem for Ruby contains possible SQL injection
    vulnerability
    Solution: upgrade to >= 1.6.1
    Alexy Mikhailichenko committed Sep 17, 2020
    Configuration menu
    Copy the full SHA
    deb4356 View commit details
    Browse the repository at this point in the history
  3. Update puma to 3.12.6

    Name: puma
    Version: 3.12.4
    Advisory: CVE-2020-11077
    Criticality: Unknown
    URL:
    GHSA-w64w-qqph-5gxm
    Title: HTTP Smuggling via Transfer-Encoding Header in Puma
    Solution: upgrade to ~> 3.12.6, >= 4.3.5
    
    Name: puma
    Version: 3.12.4
    Advisory: CVE-2020-11076
    Criticality: Unknown
    URL:
    GHSA-x7jg-6pwg-fx5h
    Title: HTTP Smuggling via Transfer-Encoding Header in Puma
    Solution: upgrade to ~> 3.12.5, >= 4.3.4
    Alexy Mikhailichenko committed Sep 17, 2020
    Configuration menu
    Copy the full SHA
    7f12037 View commit details
    Browse the repository at this point in the history
  4. Updated rack to 2.2.3

    Name: rack
    Version: 2.0.8
    Advisory: CVE-2020-8161
    Criticality: Unknown
    URL:
    https://groups.google.com/forum/#!topic/ruby-security-ann/T4ZIsfRf2eA
    Title: Directory traversal in Rack::Directory app bundled with Rack
    Solution: upgrade to ~> 2.1.3, >= 2.2.0
    
    Name: rack
    Version: 2.0.8
    Advisory: CVE-2020-8184
    Criticality: Unknown
    URL: https://groups.google.com/g/rubyonrails-security/c/OWtmozPH9Ak
    Title: Percent-encoded cookies can be used to overwrite existing
    prefixed cookie names
    Solution: upgrade to ~> 2.1.4, >= 2.2.3
    Alexy Mikhailichenko committed Sep 17, 2020
    Configuration menu
    Copy the full SHA
    50abeb9 View commit details
    Browse the repository at this point in the history
  5. Update websocket-extensions to 0.1.5

    Name: websocket-extensions
    Version: 0.1.3
    Advisory: CVE-2020-7663
    Criticality: Unknown
    URL:
    GHSA-g6wq-qcwm-j5g2
    Title: Regular Expression Denial of Service in websocket-extensions
    (RubyGem)
    Solution: upgrade to >= 0.1.5
    Alexy Mikhailichenko committed Sep 17, 2020
    Configuration menu
    Copy the full SHA
    568b96a View commit details
    Browse the repository at this point in the history