https://avo.cool logo
CVE-2024-22191 for Avo 2.46.0
# avo-2
m
Thread automatically created by gee_forr in #740893011994738751
l
Hello @few-beach-88179, yes there will be a patch with that security fix for Avo 2.x
f
excellent news! thank you 🙂
l
https://rubygems.org/gems/avo/versions/2.47.0 have the security issue fixed, thank you @User
f
nice one - just saw. Thanks so much!
i always feel so dirty adding a CVE to the bundle-audit ignore list.
l
Not ideal, I know
f
CVE-2024-22411 this time 😦
l
Hey @few-beach-88179 just tested it on
2.47.0
and is safe, no XSS in action messages
I'll try to figure out the version where it was fixed and we'll add to the list so it stop raising
Just letting you know that is safe
f
awesome - thanks. Weirdly - I ran bundler-audit again, and that CVE is no longer being raised as an issue?
l
Ah cool!
Maybe you have that one on a exclude list?
f
no - I ran the audit with no exclusions. The vuln was probably updated to ignore 2.47.0 as a vulnerable version