Skip to content

Dependency: httparty (~> 0.13.3) depends on json (~> 1.8) which has a CVE #39

Open
@pboling

Description

from bundle-audit:

Name: json
Version: 1.8.6
Advisory: CVE-2020-10663
Criticality: Unknown
URL: https://www.ruby-lang.org/en/news/2020/03/19/json-dos-cve-2020-10663/
Title: json Gem for Ruby Unsafe Object Creation Vulnerability (additional fix)
Solution: upgrade to >= 2.3.0

@grnhse Please loosen the dependency on httparty so that we can use this gem without the vulnerability.
https://www.ruby-lang.org/en/news/2020/03/19/json-dos-cve-2020-10663/

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions