Re: CVE-2023-33460, ruby-yajl affected?

2023-07-05 Thread Anton Gladky
Thanks all for the discussion. @Tobias, thanks for marking the CVE in the list. Best regards Anton Am Mi., 5. Juli 2023 um 17:56 Uhr schrieb Tobias Frost : > On Wed, Jul 05, 2023 at 09:06:15AM +, Bastien Roucaričs wrote: > > Le mercredi 5 juillet 2023, 04:52:48 UTC Anton Gladky a écrit :

Re: CVE-2023-33460, ruby-yajl affected?

2023-07-05 Thread Tobias Frost
On Wed, Jul 05, 2023 at 09:06:15AM +, Bastien Roucariès wrote: > Le mercredi 5 juillet 2023, 04:52:48 UTC Anton Gladky a écrit : > > Hello, > > > > I am looking into CVE-2023-33460 and I am not sure that ruby-yajl > > is affected. There is no direct dependency on yajl, where the vulnerability

Re: CVE-2023-33460, ruby-yajl affected?

2023-07-05 Thread Bastien Roucariès
Le mercredi 5 juillet 2023, 04:52:48 UTC Anton Gladky a écrit : > Hello, > > I am looking into CVE-2023-33460 and I am not sure that ruby-yajl > is affected. There is no direct dependency on yajl, where the vulnerability > was detected. ruby-yajl include a old version of yajl 1.01.12 The vuln

CVE-2023-33460, ruby-yajl affected?

2023-07-04 Thread Anton Gladky
Hello, I am looking into CVE-2023-33460 and I am not sure that ruby-yajl is affected. There is no direct dependency on yajl, where the vulnerability was detected. Should ruby-yajl be unmarked as affected by this CVE? Thank you Anton