From b44517ec217032eabcb113eec1ef026f69385b32 Mon Sep 17 00:00:00 2001 From: cn Date: Sat, 3 Oct 2020 11:03:01 +0200 Subject: [PATCH] gems: update webrick to version 1.6.1 - explicitly use webrick gem version with patch against CVE-2020-25613 - https://www.ruby-lang.org/en/news/2020/09/29/http-request-smuggling-cve-2020-25613/ --- openvpn-status-web.gemspec | 1 + 1 file changed, 1 insertion(+) diff --git a/openvpn-status-web.gemspec b/openvpn-status-web.gemspec index 6376b5d..a04a39b 100644 --- a/openvpn-status-web.gemspec +++ b/openvpn-status-web.gemspec @@ -28,6 +28,7 @@ Gem::Specification.new do |s| s.add_runtime_dependency 'metriks' s.add_runtime_dependency 'rack', '~> 2.0' + s.add_runtime_dependency 'webrick', '>= 1.6.1' s.add_development_dependency 'better_errors' s.add_development_dependency 'binding_of_caller'