Prior to this commit, we were seeing the following: ```console ❯ bundle exec bundle-audit check --update Updating ruby-advisory-db ... From https://github.com/rubysec/ruby-advisory-db * branch master -> FETCH_HEAD Already up to date. Updated ruby-advisory-db ruby-advisory-db: advisories: 562 advisories last updated: 2022-04-20 14:56:09 -0700 commit: 1cca55530261d16f4cd16691c1ebbae86c91c28b Name: blazer Version: 2.5.0 CVE: CVE-2022-29498 Criticality: Unknown URL: https://github.com/ankane/blazer/issues/392 Title: SQL injection for certain queries with variables Solution: upgrade to >= 2.6.0 Vulnerabilities found! ``` Blocking forem/forem#17382 |
||
|---|---|---|
| .. | ||
| assets | ||
| cache | ||