ashToronto / career_crafter_pro

A resume theming and career building web app
2 stars 1 forks source link

resolve security vulnerability CVE-2024-47220 webrick #161

Open ashToronto opened 2 months ago

ashToronto commented 2 months ago

there is a security vulnerability with webrick an internal gemfile.lock dependency - it opens us up for xss and http hijacking

webrick security vulnerability details

run a bundle update webrick and test it on staging or create reverse proxy