From 047aefc711cfbc407b10c6c06564e9128bd5226d Mon Sep 17 00:00:00 2001 From: Postmodern Date: Wed, 13 Nov 2024 14:26:10 -0800 Subject: [PATCH] Added `unaffected_versions` to CVE-2021-31799 (closes #836). * Versions below 3.11.0 are not affected. https://github.com/advisories/GHSA-ggxm-pgc9-g7fp --- gems/rdoc/CVE-2021-31799.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/gems/rdoc/CVE-2021-31799.yml b/gems/rdoc/CVE-2021-31799.yml index bfefacaf0d..b6e478fdb0 100644 --- a/gems/rdoc/CVE-2021-31799.yml +++ b/gems/rdoc/CVE-2021-31799.yml @@ -12,6 +12,8 @@ description: | run an arbitrary command execution against a user who attempts to run `rdoc` command. cvss_v3: 7.0 +unaffected_versions: + - "< 3.11.0" patched_versions: - "~> 6.1.2.1" - "~> 6.2.1.1"