Bug 31302 - ruby-nokogiri new security issue CVE-2022-23476
Summary: ruby-nokogiri new security issue CVE-2022-23476
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Pascal Terjan
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-12-19 19:12 CET by David Walser
Modified: 2023-03-13 15:58 CET (History)
1 user (show)

See Also:
Source RPM: ruby-nokogiri-1.13.8-1.mga9.src.rpm
CVE:
Status comment: Fixed upstream in 1.13.10


Attachments

Description David Walser 2022-12-19 19:12:43 CET
Fedora has issued an advisory on December 18:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/ZU7TQA34AJQYXGGIEW64UBHMFP4A5SLA/

The issue is fixed upstream in 1.13.10.
David Walser 2022-12-19 19:12:56 CET

Status comment: (none) => Fixed upstream in 1.13.10

Comment 1 Nicolas Salguero 2023-03-13 14:44:51 CET
Hi,

ruby-nokogiri-1.13.8-2.mga9 contains a patch for that issue.

Best regards,

Nico.

CC: (none) => nicolas.salguero

Comment 2 David Walser 2023-03-13 15:58:10 CET
Thanks.

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.