Skip to content

Commit

Permalink
Ignore rexml CVE-2024-43398
Browse files Browse the repository at this point in the history
  • Loading branch information
faern committed Aug 23, 2024
1 parent a1be93f commit 489f616
Show file tree
Hide file tree
Showing 2 changed files with 16 additions and 0 deletions.
8 changes: 8 additions & 0 deletions ci/ios/upload-vm/osv-scanner.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
# See repository root `osv-scanner.toml` for instructions and rules for this file.

# rexml: The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML
# that has many deep elements that have same local name attributes.
[[IgnoredVulns]]
id = "CVE-2024-43398" # GHSA-952p-6rrq-rcjv
ignoreUntil = 2024-11-23
reason = "rexml only parses trusted input (responses from Apple's APIs) in this code"
8 changes: 8 additions & 0 deletions ios/osv-scanner.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
# See repository root `osv-scanner.toml` for instructions and rules for this file.

# rexml: The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML
# that has many deep elements that have same local name attributes.
[[IgnoredVulns]]
id = "CVE-2024-43398" # GHSA-952p-6rrq-rcjv
ignoreUntil = 2024-11-23
reason = "rexml only parses trusted input (responses from Apple's APIs) in this code"

0 comments on commit 489f616

Please sign in to comment.