[Snyk] Fix for 21 vulnerabilities
Snyk has created this Merge Request to fix 21 vulnerabilities in the rubygems dependencies of this project.
Snyk changed the following file(s):
Gemfile
⚠️ Warning
Failed to update the Gemfile.lock, please update manually before merging.
Vulnerabilities that will be fixed with an upgrade:
| Issue | Score | |
|---|---|---|
| Arbitrary Code Injection SNYK-RUBY-GRAPHQL-9403760 |
674 | |
| Expired Pointer Dereference SNYK-RUBY-NOKOGIRI-10674179 |
654 | |
| Stack-based Buffer Overflow SNYK-RUBY-NOKOGIRI-10674176 |
649 | |
| Expired Pointer Dereference SNYK-RUBY-NOKOGIRI-10674184 |
649 | |
| Out-of-bounds Read SNYK-RUBY-NOKOGIRI-10674192 |
649 | |
| Allocation of Resources Without Limits or Throttling SNYK-RUBY-RACK-10074187 |
649 | |
| Allocation of Resources Without Limits or Throttling SNYK-RUBY-RACK-13378928 |
649 | |
| Allocation of Resources Without Limits or Throttling SNYK-RUBY-RACK-13378930 |
649 | |
| Allocation of Resources Without Limits or Throttling SNYK-RUBY-RACK-13378932 |
649 | |
| Allocation of Resources Without Limits or Throttling SNYK-RUBY-RACK-13535097 |
649 | |
| Relative Path Traversal SNYK-RUBY-RACK-9398129 |
649 | |
| Allocation of Resources Without Limits or Throttling SNYK-RUBY-RACK-13052974 |
624 | |
| Web Cache Poisoning SNYK-RUBY-RACK-1061917 |
616 | |
| Use After Free SNYK-RUBY-NOKOGIRI-9510795 |
576 | |
| Information Exposure SNYK-RUBY-RACK-13524628 |
559 | |
| Improper Output Neutralization for Logs SNYK-RUBY-RACK-9058602 |
559 | |
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') SNYK-RUBY-REXML-12878608 |
559 | |
| Use After Free SNYK-RUBY-NOKOGIRI-9510789 |
469 | |
| Buffer Under-read SNYK-RUBY-NOKOGIRI-9789079 |
426 | |
| Race Condition SNYK-RUBY-RACK-10074188 |
329 | |
| Stack-based Buffer Overflow SNYK-RUBY-NOKOGIRI-10674188 |
304 |
Important
- Check the changes in this PR to ensure they won't cause issues with your project.
- Max score is 1000. Note that the real score may have changed since the PR was raised.
- This PR was automatically created by Snyk using the credentials of a real user.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
Learn how to fix vulnerabilities with free interactive lessons: