From d2195b81fefc2b772a34e09ba4b43e4d98385e6b Mon Sep 17 00:00:00 2001 From: vbalbarin Date: Wed, 2 Oct 2019 15:10:12 -0400 Subject: [PATCH] Patching for CVE-2019-5477 Name: nokogiri Version: 1.10.3 Advisory: CVE-2019-5477 Criticality: High URL: https://github.com/sparklemotion/nokogiri/issues/1915 Title: Nokogiri Command Injection Vulnerability via Nokogiri::CSS::Tokenizer#load_file Solution: upgrade to >= 1.10.4 --- Gemfile.lock | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Gemfile.lock b/Gemfile.lock index 33774c5..e85ad07 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -39,7 +39,7 @@ GEM mustermann (1.0.3) netaddr (1.5.1) nio4r (2.4.0) - nokogiri (1.10.3) + nokogiri (1.10.4) mini_portile2 (~> 2.4.0) nori (2.6.0) parallel (1.17.0)