samvera / iiif_manifest

Other
10 stars 10 forks source link

Upgrade rake (again) to address security issue #47

Closed bess closed 4 years ago

bess commented 4 years ago

CVE-2020-8130 moderate severity Vulnerable versions: <= 12.3.2 Patched version: 12.3.3

There is an OS command injection vulnerability in Ruby Rake before 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character |.