VYPR

RubyGems package

rexical

pkg:gem/rexical

Vulnerabilities (1)

  • CVE-2019-5477Aug 16, 2019
    affected < 1.0.7fixed 1.0.7

    A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user input a