Skip to content
Discussion options

You must be logged in to vote

The Ruby repo updated this CVE two months ago — https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2024-54133.yml

The patched version was specified as ~> 7.2.2.1.
Version 7.2.3 is not included in this range.
That is why Trivy reported this vulnerability.

DB was updated in july

Please make sure to keep your trivy-db up to date.
Otherwise, there is a chance that you may not receive updated data (as in this case) or new advisories.

Replies: 1 comment 5 replies

Comment options

You must be logged in to vote
5 replies
@bukreevdanil09-stack
Comment options

@DmitriyLewen
Comment options

@bukreevdanil09-stack
Comment options

@DmitriyLewen
Comment options

Answer selected by bukreevdanil09-stack
@bukreevdanil09-stack
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
triage/support Indicates an issue that is a support question.
2 participants