Skip to content

Conversation

@raw-cs
Copy link

@raw-cs raw-cs commented Aug 27, 2024

Addresses CVE-2020-8130

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character \|.

@raw-cs raw-cs changed the title Bump rake 12.3 to address CVE-2020-8130 Bump rake from 10.5 to 12.3 to address CVE-2020-8130 Aug 27, 2024
@fugufish
Copy link

lol you beat me to it, but I bumped it on mine up to 13 so mine is better than yours.

@HistoireDeBabar
Copy link

Is there any update on this, or anything we can do to help get this merged?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants