Skip to content

Supply-chain security issue: CVE-2021-41098 (CVSS High in stale dependency) || Support for EOL'd ruby versions #201

@mbijon

Description

@mbijon

nokogiri <1.12.5 has a vulnerability classified as high-risk: CVE-2021-41098. However, this package is currently bundling nokogiri v1.11.0.rc2. That version 1.11.0.rc2 was released in April-2020 and appears to be in-use ONLY to maintain support for ruby v2.3 & 2.4.

Both versions of ruby have been EOL'd for more than a year (https://endoflife.date/ruby):

  • ruby 2.3 EOL 3/2019
  • ruby 2.4 EOL 3/2020
  • Even ruby 2.5 was EOL'd, in 3/2021

To remediate:
Could this module be updated to deprecate support for ruby <2.6 & require the secure nokogiri version?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions