Skip to content

Update rack gem to address vulnerability - #11954

Closed
mitchellhenke wants to merge 1 commit into
mainfrom
mitchellhenke/update-rack-1
Closed

Update rack gem to address vulnerability#11954
mitchellhenke wants to merge 1 commit into
mainfrom
mitchellhenke/update-rack-1

Conversation

@mitchellhenke

Copy link
Copy Markdown
Contributor

🛠 Summary of changes

Updates rack to fix the reported vulnerability below:

Name: rack
Version: 3.0.12
CVE: CVE-2025-27111
GHSA: GHSA-8cgq-6mh2-7j6v
Criticality: Unknown
URL: GHSA-8cgq-6mh2-7j6v
Title: Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection
Solution: update to '> 2.2.12', '> 3.0.13', '>= 3.1.11'

changelog: Internal, Maintenance, Update rack gem to address vulnerability
@mitchellhenke
mitchellhenke requested a review from a team March 6, 2025 13:56
@mitchellhenke

Copy link
Copy Markdown
Contributor Author

Currently blocked by the fix here: hashrocket/capybara-webmock#56

We are evaluating other options as well.

@mitchellhenke

Copy link
Copy Markdown
Contributor Author

Superseded by #12009

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants