File tree Expand file tree Collapse file tree 2 files changed +27
-0
lines changed Expand file tree Collapse file tree 2 files changed +27
-0
lines changed Original file line number Diff line number Diff line change
1
+ ---
2
+ gem : measured
3
+ ghsa : 29g5-m8v7-v564
4
+ url : https://github.com/Shopify/measured/security/advisories/GHSA-29g5-m8v7-v564
5
+ title : Measured is vulnerable to Path Traversal attacks during
6
+ class initialization
7
+ date : 2025-07-15
8
+ description : |
9
+ ### Impact
10
+
11
+ A path traversal vulnerability exists where an attacker
12
+ with access to manipulate inputs when initializing the
13
+ `Measured::Cache::Json class` would be able to instruct
14
+ the library to read arbitrary files.
15
+
16
+ ### Patches
17
+
18
+ Users should update to the latest version.
19
+ patched_versions :
20
+ - " >= 3.2.1"
21
+ related :
22
+ url :
23
+ - https://github.com/Shopify/measured/security/advisories/GHSA-29g5-m8v7-v564
24
+ - https://github.com/Shopify/measured/commit/d6319985a2304d97c085e3dc45c98af554f4be76
25
+ - https://github.com/advisories/GHSA-29g5-m8v7-v564
Original file line number Diff line number Diff line change 1
1
---
2
2
gem : resolv
3
3
cve : 2025-24294
4
+ ghsa : xh69-987w-hrp8
4
5
url : https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294
5
6
title : Possible Denial of Service in resolv gem
6
7
date : 2025-07-09
@@ -35,6 +36,7 @@ description: |
35
36
36
37
## History
37
38
Originally published at 2025-07-08 07:00:00 (UTC)
39
+ cvss_v3 : 5.3
38
40
patched_versions :
39
41
- " ~> 0.2.2"
40
42
- " ~> 0.3.0"
You can’t perform that action at this time.
0 commit comments