-
Notifications
You must be signed in to change notification settings - Fork 2.5k
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Upgrade rexml to 3.3.8 to fix CVE-2024-43398 #5245
Conversation
Hey @aenand could you help with the review with this? |
Absolutely! Thank you for raising this. I'll review it today |
This looks good to me from a changelog perspective. @Buitragox is performing some more in depth testing to see if the latest available version (3.3.7) works |
Thanks @aenand . should I bump the version here to |
Yes please bump to 3.3.7 |
Latest version 3.3.7 works fine |
bumped. thanks! @aenand @Buitragox |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thank you for this! This will get merged next week
there's a new version just came out, https://github.com/ruby/rexml/releases should we update to that since we haven't merged it yet? |
@Buitragox what is your deploy plan? Would you rather retest on the new version or are you planning to merge this soon? |
a66dd38
to
25fc445
Compare
done. thanks @Buitragox |
Resolves CVE-2024-43398
Tests
bundle exec rake test:local