You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This gem includes an old version of handlebars (v 3.0.2), which includes a security bug fixed in v 4.3.0. I don't know if this gem is maintained anymore, but if it is I think it would be worthwhile to update handlebars to 4.3.0 or 3.0.8.
If this gem is not maintained anymore, maybe the README could warn users about this?
It appears that there's no safe way to update handlebars without jumping all the way to Handlebars 4.7.7. I was about to volunteer to file a PR that replaces Handlebars 3.0.2 with 3.0.8, but that's not going to work anyway. I'm not up to the task of making such a large upgrade; sorry.
This gem includes an old version of handlebars (v 3.0.2), which includes a security bug fixed in v 4.3.0. I don't know if this gem is maintained anymore, but if it is I think it would be worthwhile to update handlebars to 4.3.0 or 3.0.8.
If this gem is not maintained anymore, maybe the README could warn users about this?
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19919
GHSA-w457-6q6x-cgp9
The text was updated successfully, but these errors were encountered: