You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Blazer is impacted by CVE-2019-12732 (ankane/chartkick#488), which can lead to a cross-site scripting (XSS) attack if ActiveSupport.escape_html_entities_in_json is set to false (this is not the default for Rails).
All Blazer users should upgrade Chartkick immediately.
gem'chartkick','>= 3.2'
Blazer 2.1.0 has been released that requires Chartkick 3.2 or above.
The text was updated successfully, but these errors were encountered:
Blazer is impacted by CVE-2019-12732 (ankane/chartkick#488), which can lead to a cross-site scripting (XSS) attack if
ActiveSupport.escape_html_entities_in_json
is set tofalse
(this is not the default for Rails).All Blazer users should upgrade Chartkick immediately.
Blazer 2.1.0 has been released that requires Chartkick 3.2 or above.
The text was updated successfully, but these errors were encountered: