4 ms·
Please also note from the blog post that CVE-2013-0269 refers to the "json" gem, which may not get upgraded with the rails gem updates. You may need to add it a
by travisp 14y ago
Please also note from the blog post that CVE-2013-0269 refers to the "json" gem, which may not get upgraded with the rails gem updates. You may need to add it as a separate dependency to your Gemfile to make sure you are using json version 1.7.7, 1.6.8, or 1.5.5.
- cwzwarich 14y agoShouldn't there be a way for gems maintainers to force/strongly encourage an upgrade when there is a security issue regardless of the transitive nature of the dependency?
- reedlaw 14y agoI just patched a project by updating the Gemfile with the latest Rails version and "bundle update rails" updated the json gem along with it.
- travisp 14y agoI think it depends a lot on your particular configuration, since json is only an indirect dependency in rails (i.e. it's not part of rails's gemspec). It's clear that it won't get updated for everyone, which is why this warning (to make sure json gets updated and possibly add the dependency if needed) has gone out on the rails security mailing list.
- pardner 14y agoThere are two common json gems, one if which is NOT updated when you update rails. json_pure does not seem to be updated to 1.7.7 automatically by 'bundle update rails' so if your Gemfile.lock shows your app uses json_pure (via some other gem's dependency in my case), you also need to run 'bundle update json_pure'