Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update rexml dependency #291

Open
npetrackunit opened this issue Oct 10, 2024 · 4 comments
Open

Update rexml dependency #291

npetrackunit opened this issue Oct 10, 2024 · 4 comments
Labels
dependencies Pull requests that update a dependency file enhancement New feature or request

Comments

@npetrackunit
Copy link

Is your feature request related to a problem? Please describe.
There is a DoS vulnerability in REXML gem which is included in the Starscream dependency. This vulnerability has been assigned the CVE identifier CVE-2024-39908. We strongly recommend upgrading the REXML gem.

Describe the solution you'd like
Contact Starscream since they are a dependency for your repo, adjust things on your end to remove the issue if possible.

Describe alternatives you've considered
I have contacted that repo directly with a github issue but haven't heard back for 2 weeks about this.

Additional context
Affected versions
REXML gem 3.3.2 or prior

Hi, I am posting this on your repo since I am not getting a response from the Starscream folks. If you could help out with this that would be great. This issue is being flagged in our project through a company check, and there is nothing I can do to resolve this either than remove your package.

Let me know if there is something else I can do to resolve this. Thanks :)

@npetrackunit npetrackunit added the enhancement New feature or request label Oct 10, 2024
@andrii-bodnar andrii-bodnar added good first issue Good for newcomers hacktoberfest This issue welcomes contributions for Hacktoberfest labels Oct 10, 2024
@andrii-bodnar
Copy link
Member

Hi @npetrackunit, thank you for reporting this!

Could you please share the issue you've posted to the Starscreem repository?

@andrii-bodnar andrii-bodnar added dependencies Pull requests that update a dependency file and removed good first issue Good for newcomers hacktoberfest This issue welcomes contributions for Hacktoberfest labels Oct 10, 2024
@npetrackunit
Copy link
Author

@andrii-bodnar Of course! daltoniam/Starscream#1040

Thanks for the quick reply!

@andrii-bodnar
Copy link
Member

@npetrackunit thank you for the link!

I just posted a new comment on this issue, hopefully it will get some attention from the maintainers. I see there has been no activity on this repo for a while...

@npetrackunit
Copy link
Author

@andrii-bodnar I really appreciate it! I noticed that as well, so I hope you have better luck than I did :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants