Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Address rubyzip CVE-2019-16892 #154

Closed
nfm opened this issue Oct 1, 2019 · 2 comments
Closed

Address rubyzip CVE-2019-16892 #154

nfm opened this issue Oct 1, 2019 · 2 comments

Comments

@nfm
Copy link

nfm commented Oct 1, 2019

There's a security issue in rubyzip ~> 1.0, which is mitigated in rubyzip >= 2.0.0. See rubyzip/rubyzip#403 for full details. webdrivers has a runtime dependency on rubyzip ~> 1.0.

I'm not sure if webdrivers' usage of rubyzip is vulnerable but locking to rubyzip ~> 1.0 is problematic for us as 1.x is insecure by default.

It looks like the only other breaking change in rubyzip 2.0.0 is dropping support for EOL ruby versions so hopefully bumping the dep to rubyzip ~> 2.0 is pretty painless.

Alternatively, webdrivers could opt-in to the new checks available in rubyzip >= 1.3.0 as outlined in rubyzip/rubyzip#403.

❤️

@nfm
Copy link
Author

nfm commented Oct 1, 2019

Sorry, I didn't see #153 before opening this issue.

Will leave this open for now until that merges in case anyone else goes to open an issue to track this.

@kapoorlakshya
Copy link
Collaborator

@nfm I have released v4.1.3 with the fix for this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants