You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The bootstrap-wysihtml5-rails gem at v 0.3.3.8 and earlier includes a vendored Javascript library (handlebars v 3.0.2). That library is affected by GHSA-w457-6q6x-cgp9 and fixed by handlebars v 4.3.0 or 3.0.8. There is no patched version of the bootstrap-wysihtml5-rails gem that updates this version of handlebars.
I've noticed that most of the issues in this database relate to issues in the Ruby code bundled into Ruby gems, but not necessarily issues with vendored Javascript libraries. Is this by design? If so, please close this issue. Otherwise, I can file more issues like this; I've found vulnerable vendored JS in a couple gems.
The text was updated successfully, but these errors were encountered:
The bootstrap-wysihtml5-rails gem at v 0.3.3.8 and earlier includes a vendored Javascript library (handlebars v 3.0.2). That library is affected by GHSA-w457-6q6x-cgp9 and fixed by handlebars v 4.3.0 or 3.0.8. There is no patched version of the bootstrap-wysihtml5-rails gem that updates this version of handlebars.
I've noticed that most of the issues in this database relate to issues in the Ruby code bundled into Ruby gems, but not necessarily issues with vendored Javascript libraries. Is this by design? If so, please close this issue. Otherwise, I can file more issues like this; I've found vulnerable vendored JS in a couple gems.
The text was updated successfully, but these errors were encountered: