VDB
Sign up
MEDIUM6.5

GHSA-w78q-4w34-jrjx

Publify vulnerable to code injection

Quick fix

GHSA-w78q-4w34-jrjx — publify_core: upgrade to the fixed version with the command below.

bundle update publify_core

Details

Code Injection in GitHub repository publify/publify prior to 9.2.8.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/publify_core
Introduced in: 0Fixed in: 9.2.8
Fixbundle update publify_core

References