Rexml has been gemified. Shale's gemspec doesn't require a specific version of rexml and rexml<3.2.5 is vulnerable to CVE-2021-28965. I just checked Ubuntu 20.04 LTS and got Ruby 2.7 with rexml 3.2.3 by default so this seems like a realistic concern and it would be safer if shale required a minimum rexml version.See http://www.ruby-lang.org/en/news/2021/04/05/xml-round-trip-v...
beerkg|3 years ago
zwp|3 years ago
NegativeLatency|3 years ago