USN-4922-1: Ruby vulnerability
20 April 2021
Ruby incorrectly handled XML documents.
Juho Nurminen discovered that the REXML gem bundled with Ruby incorrectly
parsed and serialized XML documents. A remote attacker could possibly use
this issue to perform an XML round-trip attack.
The problem can be corrected by updating your system to the following package versions:
In general, a standard system update will make all the necessary changes.
- USN-4922-2: ruby2.7-dev, libruby2.7, ruby2.7-doc, ruby2.7