Skip to content

[Snyk] Security upgrade nokogiri from 1.6.8.1 to 1.7.2 - #2

Open
ryanmcmorrowsnyk wants to merge 1 commit into
masterfrom
snyk-fix-d1e004a21813aa1001878e2e69b30a75
Open

[Snyk] Security upgrade nokogiri from 1.6.8.1 to 1.7.2#2
ryanmcmorrowsnyk wants to merge 1 commit into
masterfrom
snyk-fix-d1e004a21813aa1001878e2e69b30a75

Conversation

@ryanmcmorrowsnyk

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 2 vulnerabilities in the rubygems dependencies of this project.

Snyk changed the following file(s):

  • Gemfile
  • Gemfile.lock
Breaking Change Assessment! <- Click to expand>.

Breaking Change Assessment: High 🔴

This upgrade to Nokogiri 1.7.2 introduces a significant breaking change by requiring Ruby version 2.1.0 or newer. Systems running older, end-of-life Ruby versions will fail to install this gem.

Actionable Items:

  • Verify Ruby Version: Ensure your environment is running Ruby >= 2.1.0 before attempting to upgrade the Nokogiri gem.
  • Security Fixes: This version also includes important security patches for underlying libraries, addressing multiple CVEs (including CVE-2017-5029, CVE-2016-4738, CVE-2016-4658, and CVE-2016-5131).

Source: Nokogiri Changelog
Recommendation: Confirm your Ruby runtime version meets the new requirement before merging this security update.

Privacy Note 🤖: This is an AI summary generated using only our own internal data. No customer data is ever used in this process.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Arbitrary Code Execution
SNYK-RUBY-NOKOGIRI-20367
  214  
high severity Out of Bounds Memory Write
SNYK-RUBY-NOKOGIRI-20368
  195  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@corgea

corgea Bot commented Sep 22, 2025

Copy link
Copy Markdown

🐕 Corgea found the following new SCA issues in the codebase:

Package CVE Severity Version Fixed Version Ecosystem Summary
rake CVE-2020-8130 MEDIUM 11.3.0 12.3.3 RubyGems OS Command Injection in Rake
activerecord CVE-2022-32224 CRITICAL 5.0.0.1 5.2.8.1 RubyGems Active Record RCE bug with Serialized Columns
activesupport CVE-2020-8165 CRITICAL 5.0.0.1 6.0.3.1 RubyGems ActiveSupport potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
fastreader CVE-2013-2615 HIGH 1.0.8 N/A RubyGems fastreader Gem for Ruby URI Handling Arbitrary Command Injection
i18n CVE-2014-10077 HIGH 0.7.0 0.8.0 RubyGems i18n Vulnerable to Denial of Service Attack
pdfkit CVE-2013-1607 CRITICAL 0.5.2 0.5.3 RubyGems PDFKit Improper Input Validation vulnerability
rack CVE-2024-25126 MEDIUM 1.6.4 2.2.8.1 RubyGems Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)
tzinfo CVE-2022-31163 HIGH 1.2.2 1.2.10 RubyGems TZInfo relative path traversal vulnerability allows loading of arbitrary files

Showing 8 out of 29 findings. See full results

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants