uclibs / ucrate

Scholar@UC: University of Cincinnati's self-submission institutional repository
https://scholar.uc.edu
Other
5 stars 3 forks source link

Update gem puma to either '~> 5.6.7', '>= 6.3.1' #1104

Open Janell-Huyck opened 8 months ago

Janell-Huyck commented 8 months ago

Current version in Gemfile: '~> 4.3.8'

bundler-audit message:

Name: puma Version: 4.3.12 CVE: CVE-2023-40175 GHSA: GHSA-68xg-gqqm-vgj8 Criticality: Medium URL: https://github.com/puma/puma/security/advisories/GHSA-68xg-gqqm-vgj8 Title: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in puma Solution: upgrade to '~> 5.6.7', '>= 6.3.1'