From 7d80ab4c66e537402ed2f187723b67c2d1d42d93 Mon Sep 17 00:00:00 2001 From: Tim Smith Date: Wed, 18 Oct 2017 11:05:38 -0700 Subject: Use Rubygems 2.6.14 to fix CVE-2017-0903 Whitelist classes and symbols that are in loaded YAML. See CVE-2017-0903 for full details. Signed-off-by: Tim Smith --- omnibus_overrides.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/omnibus_overrides.rb b/omnibus_overrides.rb index 73d5c24f17..b02d2384db 100644 --- a/omnibus_overrides.rb +++ b/omnibus_overrides.rb @@ -1,5 +1,5 @@ # DO NOT EDIT. Generated by "rake dependencies". Edit version_policy.rb instead. -override :rubygems, version: "2.6.13" +override :rubygems, version: "2.6.14" override :bundler, version: "1.12.5" override "libffi", version: "3.2.1" override "libiconv", version: "1.15" -- cgit v1.2.1