-
Notifications
You must be signed in to change notification settings - Fork 458
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update rexml dependency (CVE-2024-39908) #948
Conversation
Is there a reason why #944 wasn't merged? This would have avoided users having to wait on this PR to merge to update REXML right? |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We're also waiting for this, @segiddins are you aware of this?
Yup, we need this too. |
Thanks for raising this PR and getting it merged. When are we likely to see a new release of Xcodeproj that incorporates this change? |
There is a DoS vulnerability in REXML gem. This vulnerability has been assigned the CVE identifier CVE-2024-39908. We strongly recommend upgrading the REXML gem.
Details
When it parses an XML that has many specific characters such as <, 0 and %>. REXML gem may take long time.
Please update REXML gem to version 3.3.2 or later.
Affected versions
REXML gem 3.3.2 or prior