Rubygems critical CVE #3246
-
A critical CVE that allows for Rubygem takeover was just published. I'm not sure whether Homebrew depends on any potentially compromised gems, but the notice provides enough details that you could probably check. Off-topic: The only method currently listed by Homebrew for reporting security vulnerabilities requires registering an account with a third party website. I really believe the barrier for reporting security concerns should be lower than that. Perhaps you could also list an email address - any free one would do, just forward the messages. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Thanks for the heads up. We lock our dependencies and review pull requests which make any updates. Based on the advice mentioned in this advisory:
We have not seen this happen to any of our Gemfile.lock files. |
Beta Was this translation helpful? Give feedback.
Thanks for the heads up. We lock our dependencies and review pull requests which make any updates.
Based on the advice mentioned in this advisory:
We have not seen this happen to any of our Gemfile.lock files.