Skip to content

Bump nokogiri to 1.10.4

Thong Kuah requested to merge bump_nokogiri-1.10.4 into master

This pulls in fix for CVE-2019-5477, where usage of Nokogiri::CSS::Tokenizer#load_file leads to potential command injection.

gitlab-ce MR : https://gitlab.com/gitlab-org/gitlab-ce/merge_requests/31701

Edited by 🤖 GitLab Bot 🤖

Merge request reports

Loading