Skip to content

Commit f3f5de3

Browse files
committed
There is an OS command injection vulnerability in Ruby Rake before 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character |.
1 parent 290f465 commit f3f5de3

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

rubycent.gemspec

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ Gem::Specification.new do |spec|
3939
spec.add_dependency 'multi_json', '~> 1.13.1'
4040

4141
spec.add_development_dependency 'bundler'
42-
spec.add_development_dependency 'rake', '~> 10.0'
42+
spec.add_development_dependency 'rake', '>= 12.3.3'
4343
spec.add_development_dependency 'rspec', '~> 3.0'
4444
spec.add_development_dependency 'webmock', '~> 3.7.5'
4545
end

0 commit comments

Comments
 (0)