realadeel / pinterest-api

Ruby gem to interact with the official Pinterest REST API
MIT License
58 stars 37 forks source link

Depends on vulnerable version of omniauth-oauth2 #17

Open vprotsan opened 6 years ago

vprotsan commented 6 years ago

Hello, github has notified me that pinterest-api is depending on a vulnerable version of the omniauth-oauth2 gem. You can find the vulnerability of omniauth-oauth2 here: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6134

Is there a way to upgrade the version?