@@ -31,55 +31,55 @@ Audit a project's `Gemfile.lock`:
31
31
Criticality: Medium
32
32
URL: http://www.osvdb.org/show/osvdb/91452
33
33
Title: XSS vulnerability in sanitize_css in Action Pack
34
- Solution: upgrade to ~> 2.3.18, ~> 3.1.12, >= 3.2.13
34
+ Solution: update to ~> 2.3.18, ~> 3.1.12, >= 3.2.13
35
35
36
36
Name: actionpack
37
37
Version: 3.2.10
38
38
Advisory: OSVDB-91454
39
39
Criticality: Medium
40
40
URL: http://osvdb.org/show/osvdb/91454
41
41
Title: XSS Vulnerability in the `sanitize` helper of Ruby on Rails
42
- Solution: upgrade to ~> 2.3.18, ~> 3.1.12, >= 3.2.13
42
+ Solution: update to ~> 2.3.18, ~> 3.1.12, >= 3.2.13
43
43
44
44
Name: actionpack
45
45
Version: 3.2.10
46
46
Advisory: OSVDB-89026
47
47
Criticality: High
48
48
URL: http://osvdb.org/show/osvdb/89026
49
49
Title: Ruby on Rails params_parser.rb Action Pack Type Casting Parameter Parsing Remote Code Execution
50
- Solution: upgrade to ~> 2.3.15, ~> 3.0.19, ~> 3.1.10, >= 3.2.11
50
+ Solution: update to ~> 2.3.15, ~> 3.0.19, ~> 3.1.10, >= 3.2.11
51
51
52
52
Name: activerecord
53
53
Version: 3.2.10
54
54
Advisory: OSVDB-91453
55
55
Criticality: High
56
56
URL: http://osvdb.org/show/osvdb/91453
57
57
Title: Symbol DoS vulnerability in Active Record
58
- Solution: upgrade to ~> 2.3.18, ~> 3.1.12, >= 3.2.13
58
+ Solution: update to ~> 2.3.18, ~> 3.1.12, >= 3.2.13
59
59
60
60
Name: activerecord
61
61
Version: 3.2.10
62
62
Advisory: OSVDB-90072
63
63
Criticality: Medium
64
64
URL: http://direct.osvdb.org/show/osvdb/90072
65
65
Title: Ruby on Rails Active Record attr_protected Method Bypass
66
- Solution: upgrade to ~> 2.3.17, ~> 3.1.11, >= 3.2.12
66
+ Solution: update to ~> 2.3.17, ~> 3.1.11, >= 3.2.12
67
67
68
68
Name: activerecord
69
69
Version: 3.2.10
70
70
Advisory: OSVDB-89025
71
71
Criticality: High
72
72
URL: http://osvdb.org/show/osvdb/89025
73
73
Title: Ruby on Rails Active Record JSON Parameter Parsing Query Bypass
74
- Solution: upgrade to ~> 2.3.16, ~> 3.0.19, ~> 3.1.10, >= 3.2.11
74
+ Solution: update to ~> 2.3.16, ~> 3.0.19, ~> 3.1.10, >= 3.2.11
75
75
76
76
Name: activesupport
77
77
Version: 3.2.10
78
78
Advisory: OSVDB-91451
79
79
Criticality: High
80
80
URL: http://www.osvdb.org/show/osvdb/91451
81
81
Title: XML Parsing Vulnerability affecting JRuby users
82
- Solution: upgrade to ~> 3.1.12, >= 3.2.13
82
+ Solution: update to ~> 3.1.12, >= 3.2.13
83
83
84
84
Unpatched versions found!
85
85
0 commit comments