Changes between Initial Version and Version 1 of Ticket #12456, comment 1


Ignore:
Timestamp:
08/30/2019 04:06:33 PM (5 years ago)
Author:
Bruce Dubbs

Legend:

Unmodified
Added
Removed
Modified
  • Ticket #12456, comment 1

    initial v1  
    11This seems to be a security release for rdoc, fixing a vulnerability from 2012 and 2015.
    22
     3
     4There are multiple vulnerabilities about Cross-Site Scripting (XSS) in jQuery shipped with RDoc which bundled in Ruby. All Ruby users are recommended to update Ruby to the latest release which includes the fixed version of RDoc.
    35{{{
    4 There are multiple vulnerabilities about Cross-Site Scripting (XSS) in jQuery shipped with RDoc which bundled in Ruby. All Ruby users are recommended to update Ruby to the latest release which includes the fixed version of RDoc.
    56Details
    67
     
    910    CVE-2012-6708
    1011    CVE-2015-9251
    11 
     12}}}
    1213It is strongly recommended for all Ruby users to upgrade your Ruby installation or take one of the following workarounds as soon as possible. You also have to re-generate existing RDoc documentations to completely mitigate the vulnerabilities.
    1314Affected Versions
    14 
     15{{{
    1516    Ruby 2.3 series: all
    1617    Ruby 2.4 series: 2.4.6 and earlier
     
    1819    Ruby 2.6 series: 2.6.3 and earlier
    1920    prior to master commit f308ab2131ee675000926540cbb8c13c91dc3be5
    20 
     21}}}
    2122Required actions
    2223
     
    3839
    3940Thanks to Chris Seaton for reporting the issue.
     41{{{
    4042History
    4143