You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
yard vulnerability has been present in penthouse.gemspec since Dec 2017. We need to upgrade to 0.9.11 or later.
This needs to be complete by April 2019.
Due to time passed, I would suggest updating to the very latest version, if greater than 0.9.11, unless an issue is identified with doing so.
Vulnerability details:
lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.
The text was updated successfully, but these errors were encountered:
yard vulnerability has been present in penthouse.gemspec since Dec 2017. We need to upgrade to 0.9.11 or later.
This needs to be complete by April 2019.
Due to time passed, I would suggest updating to the very latest version, if greater than 0.9.11, unless an issue is identified with doing so.
Vulnerability details:
lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.
The text was updated successfully, but these errors were encountered: