Skip to content

TECH-17399: switch out rr for rspec-mocks

Security Scanner as a Service / Bundle Audit failed Feb 4, 2025 in 0s

Bundler Audit Summary

Vulnerabilities found. Please address them.

Details

CVEs were found when running bundle-audit
If you need to ignore or snooze a CVE, the list is configured here: .invoca/ssaas/bundle_audit_ignore.yaml

Annotations

Check failure on line 22 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L22

          actionmailer
          Warning Message: https://github.com/rails/rails/security/advisories/GHSA-h47h-mwp9-c6q6
          CVE:             CVE-2024-47889
          Severity:        

Check failure on line 11 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L11

          actionpack
          Warning Message: https://discuss.rubyonrails.org/t/cve-2023-28362-possible-xss-via-user-supplied-values-to-redirect-to/83132
          CVE:             CVE-2023-28362
          Severity:        medium

Check failure on line 11 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L11

          actionpack
          Warning Message: https://github.com/rails/rails/security/advisories/GHSA-fwhr-88qx-h9g7
          CVE:             CVE-2024-28103
          Severity:        medium

Check failure on line 11 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L11

          actionpack
          Warning Message: https://github.com/rails/rails/security/advisories/GHSA-x76w-6vjr-8xgj
          CVE:             CVE-2024-41128
          Severity:        

Check failure on line 11 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L11

          actionpack
          Warning Message: https://github.com/rails/rails/security/advisories/GHSA-vfg9-r3fq-jvx4
          CVE:             CVE-2024-47887
          Severity:        

Check failure on line 11 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L11

          actionpack
          Warning Message: https://github.com/rails/rails/security/advisories/GHSA-vfm5-rmrh-j26v
          CVE:             CVE-2024-54133
          Severity:        

Check failure on line 36 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L36

          actiontext
          Warning Message: https://github.com/rails/rails/security/advisories/GHSA-wwhv-wxv9-rpgw
          CVE:             CVE-2024-47888
          Severity:        

Check failure on line 19 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L19

          activestorage
          Warning Message: https://discuss.rubyonrails.org/t/possible-sensitive-session-information-leak-in-active-storage/84945
          CVE:             CVE-2024-26144
          Severity:        medium

Check failure on line 12 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L12

          activesupport
          Warning Message: https://github.com/rails/rails/releases/tag/v7.0.7.1
          CVE:             CVE-2023-38037
          Severity:        medium

Check failure on line 41 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L41

          nokogiri
          Warning Message: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-r95h-9x8f-r3f7
          CVE:             GHSA-r95h-9x8f-r3f7
          Severity:        

Check failure on line 41 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L41

          nokogiri
          Warning Message: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-xc9x-jj77-9p9j
          CVE:             GHSA-xc9x-jj77-9p9j
          Severity:        

Check failure on line 32 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L32

          rack
          Warning Message: https://discuss.rubyonrails.org/t/denial-of-service-vulnerability-in-rack-content-type-parsing/84941
          CVE:             CVE-2024-25126
          Severity:        medium

Check failure on line 32 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L32

          rack
          Warning Message: https://discuss.rubyonrails.org/t/possible-dos-vulnerability-with-range-header-in-rack/84944
          CVE:             CVE-2024-26141
          Severity:        

Check failure on line 32 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L32

          rack
          Warning Message: https://discuss.rubyonrails.org/t/possible-denial-of-service-vulnerability-in-rack-header-parsing/84942
          CVE:             CVE-2024-26146
          Severity:        

Check failure on line 166 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L166

          rexml
          Warning Message: https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh
          CVE:             CVE-2024-35176
          Severity:        medium

Check failure on line 166 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L166

          rexml
          Warning Message: https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8
          CVE:             CVE-2024-39908
          Severity:        medium

Check failure on line 166 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L166

          rexml
          Warning Message: https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41123
          CVE:             CVE-2024-41123
          Severity:        medium

Check failure on line 166 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L166

          rexml
          Warning Message: https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41946
          CVE:             CVE-2024-41946
          Severity:        medium

Check failure on line 166 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L166

          rexml
          Warning Message: https://github.com/ruby/rexml/security/advisories/GHSA-vmwr-mc7x-5vc3
          CVE:             CVE-2024-43398
          Severity:        medium

Check failure on line 166 in Gemfile.lock

See this annotation in the file changed.

@security-scanner-as-a-service security-scanner-as-a-service / Bundle Audit

Gemfile.lock#L166

          rexml
          Warning Message: https://github.com/ruby/rexml/security/advisories/GHSA-2rxp-v6pw-ch6m
          CVE:             CVE-2024-49761
          Severity:        high