File tree Expand file tree Collapse file tree 2 files changed +27
-0
lines changed Expand file tree Collapse file tree 2 files changed +27
-0
lines changed Original file line number Diff line number Diff line change 1+ ---
2+ gem : measured
3+ ghsa : 29g5-m8v7-v564
4+ url : https://github.com/Shopify/measured/security/advisories/GHSA-29g5-m8v7-v564
5+ title : Measured is vulnerable to Path Traversal attacks during
6+ class initialization
7+ date : 2025-07-15
8+ description : |
9+ ### Impact
10+
11+ A path traversal vulnerability exists where an attacker
12+ with access to manipulate inputs when initializing the
13+ `Measured::Cache::Json class` would be able to instruct
14+ the library to read arbitrary files.
15+
16+ ### Patches
17+
18+ Users should update to the latest version.
19+ patched_versions :
20+ - " >= 3.2.1"
21+ related :
22+ url :
23+ - https://github.com/Shopify/measured/security/advisories/GHSA-29g5-m8v7-v564
24+ - https://github.com/Shopify/measured/commit/d6319985a2304d97c085e3dc45c98af554f4be76
25+ - https://github.com/advisories/GHSA-29g5-m8v7-v564
Original file line number Diff line number Diff line change 11---
22gem : resolv
33cve : 2025-24294
4+ ghsa : xh69-987w-hrp8
45url : https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294
56title : Possible Denial of Service in resolv gem
67date : 2025-07-09
@@ -35,6 +36,7 @@ description: |
3536
3637 ## History
3738 Originally published at 2025-07-08 07:00:00 (UTC)
39+ cvss_v3 : 5.3
3840patched_versions :
3941 - " ~> 0.2.2"
4042 - " ~> 0.3.0"
You can’t perform that action at this time.
0 commit comments