fgrehm / letter_opener_web

A web interface for browsing Ruby on Rails sent emails
MIT License
711 stars 111 forks source link

Bump rexml to v3.3.2 #139

Open rajraj opened 2 months ago

rajraj commented 2 months ago

The REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as <, 0 and %>.

The REXML gem 3.3.2 or later include the patches to fix these vulnerabilities.

https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8