3 ms·
It appears that you failed to read the data correctly. He says that 66% of the Gemfiles examined contained any vulnerability and 13% of them contained a 5+ issu
by euank 12y ago
It appears that you failed to read the data correctly. He says that 66% of the Gemfiles examined contained any vulnerability and 13% of them contained a 5+ issue.
That doesn't even mean an exploit btw. Some of those gems might be in the Gemfile but never actually used (deprecated but not removed, hence not updated), or the vulnerable component might never be used. The gem might only be used on internal data, not user-manipulateable data.
Furthermore, you can't extrapolate 13% of the examined gemfiles containing such an issue to all gemfiles, which you did.
The fact that it's reported certainly doesn't mean it will be fixed in all downstreams (what this article refers to). Do you read every CVE? Every single one? Didn't think so. Most gems are relatively unpopular and any issues in them won't be widely publicized. Sure, Rails issues are shouted far and wide, but most of the rest are easy to miss.
Hell, some CVEs don't even get fixed in the gem itself, let alone all the consumers of that gem; the gem just remains vulnerable because there's no maintainer or the maintainer insists that it's "not an issue".
Please don't make such misinformed comments without even reading the article with sufficient attention to detail to get the statistic right.