-
Notifications
You must be signed in to change notification settings - Fork 85
Closed
Labels
triagedJira issue has been created for thisJira issue has been created for this
Description
Ruby announced a vulnerability in REXML with a CVSS score of 6.6: GHSA-2rxp-v6pw-ch6m
This vulnerability does not affect Ruby 3.2 or later. We should probably assume that this affects Ruby 2.7, which we still use in agent-runtime-7.x.
We need to patch REXML in Ruby 2.7 to address this vulnerability.
It seems this is the commit in the REXML gem that addresses the vulnerability: ruby/rexml@ce59f2e
Metadata
Metadata
Assignees
Labels
triagedJira issue has been created for thisJira issue has been created for this