From 71ee0de2e805a836ccb09384811596d002677c2c Mon Sep 17 00:00:00 2001 From: Thomas Burkhalter Date: Tue, 30 Apr 2019 10:05:40 +0200 Subject: [PATCH] Update Nokogiri to fix vulnerability Name: nokogiri Version: 1.10.1 Advisory: CVE-2019-11068 Criticality: Unknown URL: https://github.com/sparklemotion/nokogiri/issues/1892 Title: Nokogiri gem, via libxslt, is affected by improper access control vulnerability Solution: upgrade to >= 1.10.3 --- Gemfile.lock | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Gemfile.lock b/Gemfile.lock index 61cb3d412..744318675 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -255,7 +255,7 @@ GEM rails (>= 3.2.0) net-ldap (0.16.1) nio4r (2.3.1) - nokogiri (1.10.1) + nokogiri (1.10.3) mini_portile2 (~> 2.4.0) paper_trail (10.2.1) activerecord (>= 4.2, < 6.1)