Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update rexml dependency (CVE-2024-39908) #948

Merged
merged 2 commits into from
Jul 19, 2024

Conversation

bmedenwald
Copy link
Contributor

There is a DoS vulnerability in REXML gem. This vulnerability has been assigned the CVE identifier CVE-2024-39908. We strongly recommend upgrading the REXML gem.

Details
When it parses an XML that has many specific characters such as <, 0 and %>. REXML gem may take long time.

Please update REXML gem to version 3.3.2 or later.

Affected versions
REXML gem 3.3.2 or prior

@marknorgren
Copy link

Is there a reason why #944 wasn't merged?

This would have avoided users having to wait on this PR to merge to update REXML right?

xcodeproj.gemspec Outdated Show resolved Hide resolved
Copy link

@setoelkahfi setoelkahfi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're also waiting for this, @segiddins are you aware of this?

@samfranz
Copy link

Yup, we need this too.

@segiddins segiddins merged commit a234cae into CocoaPods:master Jul 19, 2024
4 checks passed
@iosdevben
Copy link

Thanks for raising this PR and getting it merged.

When are we likely to see a new release of Xcodeproj that incorporates this change?

@AliSoftware
Copy link
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

8 participants