Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

rubyzip 1.2.1 dependency is shown to have security vulnerabilities. #599

Open
waterjump opened this issue Aug 28, 2018 · 2 comments
Open
Labels
Done in caxlsx This has already been solved in the caxlsx fork.

Comments

@waterjump
Copy link

To follow up on this issue, rubyzip 1.2.1 is now also shown to have security vulnerabilities. See details here: rubyzip/rubyzip#369

Solution: Disable rubyzip or apply a patch whenever one becomes available.

waterjump added a commit to mes/axlsx that referenced this issue Sep 7, 2018
The rubyzip gem version 1.2.1 contains a security vulnerability allowing
absolute path traversal.  More details can be found here:

rubyzip/rubyzip#369

This change addresses the issue by specifying a rubyzip version greater
than or equal to 1.2.2.

Solves issue randym#599
@bashcoder
Copy link

Rubyzip is now released at 1.2.2 on Rubygems.org which resolves this vulnerability, according to bundler audit.

https://rubygems.org/gems/rubyzip

@mdavidn
Copy link

mdavidn commented Oct 29, 2018

See #536.

rozhok added a commit to rozhok/axlsx that referenced this issue May 23, 2019
Bump rubyzip version.
@noniq noniq added the Done in caxlsx This has already been solved in the caxlsx fork. label Dec 15, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Done in caxlsx This has already been solved in the caxlsx fork.
Projects
None yet
Development

No branches or pull requests

4 participants