14:27:46 14:28:09 @ruby@ruby.social
icon

We disclosed two CVEs for the default gems today.

* ruby-lang.org/en/news/2024/03/
* ruby-lang.org/en/news/2024/03/

We recommend to upgrade them for keep your code as safety.

CVE-2024-27280: Buffer overread vulnerability in StringIO
CVE-2024-27281: RCE vulnerability with .rdoc_options in RDoc