You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Commit 2ecd40e updates Xerces-Java to v2.12.0 which according to the NVD entry linked above addresses this vulnerability.
I'll also note that we've scheduled work on the two following issues to help make versions of vendored Java libraries both more discoverable and easier to maintain and update:
Credit for reporting this vulnerability to Nokogiri Core goes to David Moore @grajagandev who works at Looker. Thanks, David!
This issue is being opened for nokogiri core to triage this vulnerability within the context of Nokogiri.
CVE-2012-0881 Resources
Vulnerabile versions of Xerces-Java is present in JRuby versions of the Nokogiri gem from v1.5.0 to v1.8.5, inclusive.
Mitigation: (once Nokogiri v1.9.0 is released) JRuby users should upgrade to Nokogiri v1.9.0
The text was updated successfully, but these errors were encountered: