Skip to content

Commit 9637f37

Browse files
authored
Update CVE-2019-13354.yml
Note that 0.0.8 was released.
1 parent f39d4a5 commit 9637f37

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

gems/strong_password/CVE-2019-13354.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,10 @@ description: |
1010
malicious actor published v0.0.7 containing malicious code that enables an attacker
1111
to execute remote code in production.
1212
13-
Downgrade `strong_password` to v0.0.6 to ensure no malicious code execution is possible.
13+
Upgrade `strong_password` to v0.0.8 to ensure no malicious code execution is possible.
14+
15+
patched_versions:
16+
- ">= 0.0.8"
1417

1518
unaffected_versions:
1619
- "!= 0.0.7"

0 commit comments

Comments
 (0)