Skip to content

Commit fb89ca4

Browse files
[AUTO-CHERRYPICK] [AUTOPATCHER-CORE] Upgrade rubygem-rexml to 3.3.9 fix CVE-2024-49761 - branch 3.0-dev (#13908)
Co-authored-by: Pawel Winogrodzki <pawelwi@microsoft.com>
1 parent b5fd7cd commit fb89ca4

3 files changed

Lines changed: 9 additions & 6 deletions

File tree

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
2-
"Signatures": {
3-
"rexml-3.3.4.tar.gz": "c6ab9da9502b2a5e824925de5f5774d9222c377d0537393f560fba71e0f868c7"
4-
}
2+
"Signatures": {
3+
"rexml-3.3.9.tar.gz": "c382728a4b88e7edf2f6d76ea43f837ecac1e89a76d65b15ba18498b263d3ace"
4+
}
55
}

SPECS/rubygem-rexml/rubygem-rexml.spec

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
%global gem_name rexml
33
Summary: REXML is an XML toolkit for Ruby
44
Name: rubygem-%{gem_name}
5-
Version: 3.3.4
5+
Version: 3.3.9
66
Release: 1%{?dist}
77
License: BSD
88
Vendor: Microsoft Corporation
@@ -34,6 +34,9 @@ gem install -V --local --force --install-dir %{buildroot}/%{gemdir} %{gem_name}-
3434
%{gemdir}
3535

3636
%changelog
37+
* Wed May 21 2025 CBL-Mariner Servicing Account <cblmargh@microsoft.com> - 3.3.9-1
38+
- Auto-upgrade to 3.3.9 - fix CVE-2024-49761
39+
3740
* Fri Aug 9 2024 Bhagyashri Pathak <bhapathak@microsoft.com> - 3.3.4-1
3841
- Upgrade to 3.3.4 to resolve CVE-2024-39908
3942

cgmanifest.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27154,8 +27154,8 @@
2715427154
"type": "other",
2715527155
"other": {
2715627156
"name": "rubygem-rexml",
27157-
"version": "3.3.4",
27158-
"downloadUrl": "https://github.com/ruby/rexml/archive/refs/tags/v3.3.4.tar.gz"
27157+
"version": "3.3.9",
27158+
"downloadUrl": "https://github.com/ruby/rexml/archive/refs/tags/v3.3.9.tar.gz"
2715927159
}
2716027160
}
2716127161
},

0 commit comments

Comments
 (0)