Skip to content

GHSA SYNC: 1 brand new unreviewed advisories#969

Closed
jasnow wants to merge 1 commit intorubysec:masterfrom
jasnow:ghsa-syncbot-2026-01-22-12_54_00
Closed

GHSA SYNC: 1 brand new unreviewed advisories#969
jasnow wants to merge 1 commit intorubysec:masterfrom
jasnow:ghsa-syncbot-2026-01-22-12_54_00

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Jan 22, 2026

GHSA SYNC: 1 brand new unreviewed advisories

Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Before we flag all versions of Ruby as being vulnerable due to issues in stdlib gems, will need some confirmation here.

- Unclear when or if this was patched.
cvss_v2: 5.0
cvss_v3: 5.3
notes: Never patched
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this is still unpatched?

Also, WEBrick was moved out of Ruby and into a separate gem as of Ruby 3.0.0. I feel like >= 3.0.0 should technically be the patched_versions.

requests, which might allow remote attackers to inject arbitrary text
into log files or bypass intended address parsing via a crafted header.

## Can only have one "notes:" field for adding these notes here:
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

notes: is free form text. This additional information should be put into notes:. The additional URLs can also be added to the related urls list.

developers can cause arbitrary code execution.
cvss_v2: 7.5
cvss_v3: 9.8
notes: "Never patched"
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it really fair to flag all Ruby versions because of a stdlib gem that is not required by default and can only be used on a Windows system? Perhaps this should go into gems/win32ole/?

@jasnow
Copy link
Contributor Author

jasnow commented Jan 31, 2026

All good issues stated above. Think this PR has too many open questions so I am going to cancel it.

@jasnow jasnow closed this Jan 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants