Project

General

Profile

Actions

Bug #21130

closed

Update net-imap for ruby 3.2, 3.3, 3.4

Added by nevans (Nicholas Evans) 3 months ago. Updated 3 months ago.

Status:
Closed
Assignee:
-
Target version:
-
[ruby-core:120960]

Description

The bundled versions are vulnerable to CVE-2024-25186 (GHSA-7fc5-f82f-cx69). Fixing the issue requires upgrading to v0.3.8, v0.4.19, or v0.5.4.

The workaround is to uninstall the vulnerable bundled versions and gem install net-imap.

Security Advisory Links:

Actions #1

Updated by nevans (Nicholas Evans) 3 months ago

  • Description updated (diff)
Actions #2

Updated by hsbt (Hiroshi SHIBATA) 3 months ago

  • Status changed from Open to Closed
  • Backport changed from 3.1: UNKNOWN, 3.2: UNKNOWN, 3.3: UNKNOWN, 3.4: UNKNOWN to 3.1: UNKNOWN, 3.2: REQUIRED, 3.3: REQUIRED, 3.4: REQUIRED

Updated by k0kubun (Takashi Kokubun) 3 months ago

  • Backport changed from 3.1: UNKNOWN, 3.2: REQUIRED, 3.3: REQUIRED, 3.4: REQUIRED to 3.1: UNKNOWN, 3.2: REQUIRED, 3.3: REQUIRED, 3.4: DONE
Actions #4

Updated by hsbt (Hiroshi SHIBATA) 3 months ago

  • Backport changed from 3.1: UNKNOWN, 3.2: REQUIRED, 3.3: REQUIRED, 3.4: DONE to 3.1: UNKNOWN, 3.2: DONE, 3.3: DONE, 3.4: DONE
Actions

Also available in: Atom PDF

Like0
Like0Like0Like0Like0