From: deivid Date: 2021-12-26T09:31:55+00:00 Subject: [ruby-core:106825] [Ruby master Bug#18431] Ruby 2.6.9, bundler 1.17.2 and CVE-2021-43809 Issue #18431 has been updated by deivid (David Rodr��guez). How is the score for vulnerabilities calculated? I tried to set the score myself to "Low" in the Github Advisory, because the chances that this issue is ever explored seemed very low to me. I also run a CVSS severity calculator by answering some questions and depending on the answers I gave (some of them I was not sure what the best answer was) I would get a Low or Medium score. Where does this 7.3 number come from? In principle I totally understand that @hsbt doesn't plan to update it. ---------------------------------------- Bug #18431: Ruby 2.6.9, bundler 1.17.2 and CVE-2021-43809 https://bugs.ruby-lang.org/issues/18431#change-95636 * Author: npic1 (Nat Pic1) * Status: Closed * Priority: Normal * Assignee: hsbt (Hiroshi SHIBATA) * Backport: 2.6: UNKNOWN, 2.7: UNKNOWN, 3.0: UNKNOWN ---------------------------------------- Hi, Ruby 2.6.9 ships with bundler 1.17.2, which is affected by CVE-2021-43809. Is there a plan to upgrade it to resolve the issue? I saw that in the past, there was an upgrade and then a downgrade because of some issue: https://git.ruby-lang.org/ruby.git/commit/?id=91533d9ab17a08385381d87991e01e8674e069a1 Thanks a lot, Regards Nat -- https://bugs.ruby-lang.org/ Unsubscribe: