apotonick / kaminari-cells

Kaminari pagination in Cells.
MIT License
23 stars 15 forks source link

Kaminari 1.2.1 patch for XSS vulnerability #11

Open gffuentes opened 4 years ago

gffuentes commented 4 years ago

hello!

Looks like a vulnerability was found in Kaminari and then patched in 1.2.1. (https://groups.google.com/forum/?utm_medium=email&utm_source=footer#!msg/ruby-security-ann/1wDvZ6Aaoo8/sBL9aWtLAQAJ)

Would it be possible to update the dependency?

Thank you!

ramontayag commented 4 years ago

The dependency is "~> 1.2.0", which means you can go from 1.2.0 to 1.2.infinity.

See https://stackoverflow.com/questions/5170547/what-does-tilde-greater-than-mean-in-ruby-gem-dependencies