From 4a41ba03018166803cf17303f53bd9fcbcd50625 Mon Sep 17 00:00:00 2001 From: Victor Koronen Date: Thu, 1 Nov 2018 22:05:35 +0100 Subject: [PATCH] Bump loofah to address CVE-2018-16468 As reported by `bundler-audit`: Name: loofah Version: 2.2.1 Advisory: CVE-2018-16468 Criticality: Unknown URL: https://github.com/flavorjones/loofah/issues/154 Title: Loofah XSS Vulnerability Solution: upgrade to >= 2.2.3 --- Gemfile.lock | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Gemfile.lock b/Gemfile.lock index 1105a17ea..46186ef83 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -65,7 +65,7 @@ GEM concurrent-ruby (~> 1.0) json (1.8.6) kgio (2.11.2) - loofah (2.2.1) + loofah (2.2.3) crass (~> 1.0.2) nokogiri (>= 1.5.9) method_source (0.8.2)