From b7f4e98001b856207999c55f386f538d75b6fb24 Mon Sep 17 00:00:00 2001 From: Wilson Silva Date: Thu, 30 May 2024 16:50:42 +0100 Subject: [PATCH] Update rexml to 3.2.8 to fix CVE-2024-35176 https://www.ruby-lang.org/en/news/2024/05/16/dos-rexml-cve-2024-35176/ --- Gemfile.lock | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/Gemfile.lock b/Gemfile.lock index 90b2570..b2367a7 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -69,7 +69,8 @@ GEM rainbow (3.1.1) rake (13.2.1) regexp_parser (2.9.0) - rexml (3.2.6) + rexml (3.2.8) + strscan (>= 3.0.9) rubocop (1.63.4) json (~> 2.3) language_server-protocol (>= 3.17.0) @@ -84,6 +85,7 @@ GEM rubocop-ast (1.31.2) parser (>= 3.3.0.4) ruby-progressbar (1.13.0) + strscan (3.1.0) unicode-display_width (2.5.0) webmock (3.23.0) addressable (>= 2.8.0)