Project

General

Profile

Actions

Bug #18431

closed

Ruby 2.6.9, bundler 1.17.2 and CVE-2021-43809

Added by npic1 (Nat Pic1) almost 3 years ago. Updated almost 3 years ago.

Status:
Closed
Target version:
-
[ruby-core:106811]

Description

Hi,
Ruby 2.6.9 ships with bundler 1.17.2, which is affected by CVE-2021-43809.
Is there a plan to upgrade it to resolve the issue?

I saw that in the past, there was an upgrade and then a downgrade because of some issue:
https://git.ruby-lang.org/ruby.git/commit/?id=91533d9ab17a08385381d87991e01e8674e069a1

Thanks a lot,
Regards
Nat

Actions

Also available in: Atom PDF

Like0
Like0Like0Like0Like0Like0