Skip to content

Resolve "Bump rubygems to latest version to address CVE-2017-0903"

Balasankar 'Balu' C requested to merge 3429-bump-rubygems into master

Closes #3429

Upstream changelog

=== 2.6.14 / 2017-10-09

Security fixes:

* Whitelist classes and symbols that are in loaded YAML.
  See CVE-2017-0903 for full details.
  Fix by Aaron Patterson.
Edited by Balasankar 'Balu' C

Merge request reports