Updated ruby-mechanize packages fix a security vulnerability
Publication date: 12 Mar 2021Modification date: 12 Mar 2021
Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2021-21289
Description
In Mechanize, from v2.0.0 until v2.7.7, there is a command injection vulnerability. Affected versions of Mechanize allow for OS commands to be injected using several classes' methods which implicitly use Ruby's Kernel#open method (CVE-2021-21289).
References
SRPMS
7/core
- ruby-mechanize-2.7.6-2.1.mga7
8/core
- ruby-mechanize-2.7.6-3.1.mga8