Skip to content

Commit 058e87f

Browse files
committed
update CHANGELOG with complete CVE information
1 parent 9285251 commit 058e87f

File tree

1 file changed

+12
-1
lines changed

1 file changed

+12
-1
lines changed

CHANGELOG.md

+12-1
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,18 @@ Nokogiri follows [Semantic Versioning](https://semver.org/), please see the [REA
88

99
### Security
1010

11-
[CRuby] Vendored libxml2 upgraded to v2.9.12 which addresses [CVE-2021-3541](https://blog.hartwork.org/posts/cve-2021-3541-parameter-laughs-fixed-in-libxml2-2-9-11/). [[#2233](https://github.com/sparklemotion/nokogiri/issues/2233)]
11+
[CRuby] Vendored libxml2 upgraded to v2.9.12 which addresses:
12+
13+
- [CVE-2019-20388](https://security.archlinux.org/CVE-2019-20388)
14+
- [CVE-2020-24977](https://security.archlinux.org/CVE-2020-24977)
15+
- [CVE-2021-3517](https://security.archlinux.org/CVE-2021-3517)
16+
- [CVE-2021-3518](https://security.archlinux.org/CVE-2021-3518)
17+
- [CVE-2021-3537](https://security.archlinux.org/CVE-2021-3537)
18+
- [CVE-2021-3541](https://security.archlinux.org/CVE-2021-3541)
19+
20+
Note that two additional CVEs were addressed upstream but are not relevant to this release. [CVE-2021-3516](https://security.archlinux.org/CVE-2021-3516) via `xmllint` is not present in Nokogiri, and [CVE-2020-7595](https://security.archlinux.org/CVE-2020-7595) has been patched in Nokogiri since v1.10.8 (see #1992).
21+
22+
Please see #2233 for a more complete analysis of these CVEs and patches.
1223

1324

1425
### Dependencies

0 commit comments

Comments
 (0)