NYULibraries / spatial_data_repository

NYU's GeoBlacklight instance @ geo.nyu.edu
https://geo.nyu.edu
6 stars 2 forks source link

REXML has a DoS Vulnerability #324

Closed spilth closed 3 months ago

spilth commented 3 months ago

After merging #323 the build failed due to a vulnerability in the rexml gem.

Name: rexml Version: 3.3.1 CVE: CVE-2024-39908 Criticality: Unknown URL: https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8 Title: DoS in REXML Solution: upgrade to '>= 3.3.2'

We need to upgrade from 3.3.1 to 3.3.2 to address this issue.

spilth commented 3 months ago

Resolved by #325