Skip to content

Bump rake from 10.5 to 12.3 to address CVE-2020-8130 #78

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

raw-cs
Copy link

@raw-cs raw-cs commented Aug 27, 2024

Addresses CVE-2020-8130

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character \|.

@raw-cs raw-cs changed the title Bump rake 12.3 to address CVE-2020-8130 Bump rake from 10.5 to 12.3 to address CVE-2020-8130 Aug 27, 2024
@fugufish
Copy link

lol you beat me to it, but I bumped it on mine up to 13 so mine is better than yours.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants