Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
(PA-6507) Update gem rexml from default to 3.2.7 for CVE-2024-35176
- The CVE was mitigated from rexml version 3.2.7. - Patching for the CVE wasn't getting applied cleanly and had a lot of conflicts. So updated the gem version to 3.2.7 in the rexml component file. - Added the change to _shared-agent-components since the CVE impacts both agent-runtime-main (ruby 3.2.4 using rexml 3.2.6) and agent-runtime-7.x (ruby 2.7.8 using rexml 3.2.3). - Added rubygems-strscan component with version 3.0.9 because rexml 3.2.7 requires strscan 3.0.9 but agent-runtime rubies come with older version of it.
- Loading branch information