You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.
Nokogiri prior to version 1.10.5 contains a vulnerable version of libxslt. Nokogiri version 1.10.5 upgrades the dependency to libxslt 1.1.34, which contains a patch for this issue.
Description
Type confusion in
xsltNumberFormatGetMultipleLevel
prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.Nokogiri prior to version 1.10.5 contains a vulnerable version of libxslt. Nokogiri version 1.10.5 upgrades the dependency to libxslt 1.1.34, which contains a patch for this issue.
Informations
Manifest Path: Gemfile.lock
Please look at dependabot report: https://github.com/swipely/swipely-bss-oodd/security/dependabot/120
The text was updated successfully, but these errors were encountered: