Skip to content

Ten new vulnerabilities in Rack, GlobalID, and Rails this week #536

Closed
@ddalcino

Description

@ddalcino

I just saw this stack of 10 new announcements over the past two days: https://discuss.rubyonrails.org/c/security-announcements/9

Usually, I rely on bundler-audit to tell me when there are new vulnerabilities, but in this case I happened to check the Rails security announcement page, saw these, and realized that bundler-audit was not telling me about them. That's when I came here.

All of these vulnerabilities definitely exist in the Github Advisory Database; maybe the rake sync_github_advisories task needs to be run?

Also, much thanks for maintaining this repository; it's a lifesaver!

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions