Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vulnerability in rack #488

Closed
abhiram-ramesh opened this issue Oct 27, 2021 · 1 comment · May be fixed by #467
Closed

vulnerability in rack #488

abhiram-ramesh opened this issue Oct 27, 2021 · 1 comment · May be fixed by #467

Comments

@abhiram-ramesh
Copy link

Hello,

version of rack, mailcatcher is using has some critical vulnerability.
Is there any plan to to upgrade rack version to 2.2.3?

https://nvd.nist.gov/vuln/search/results?form_type=Advanced&results_type=overview&search_type=all&cpe_vendor=cpe%3A%2F%3Arack_project&cpe_product=cpe%3A%2F%3Arack_project%3Arack&cpe_version=cpe%3A%2F%3Arack_project%3Arack%3A1.6.13

@sj26
Copy link
Owner

sj26 commented Nov 1, 2021

Thanks for reaching out!

Rack 2 is a big upgrade, I think.

There is a long term effort to refactor mailcatcher onto using async, decoupling from eventmachine, thin, skinny, and sinatra, and then modernising from there.

MailCatcher is designed to be a local development tool run and accessible on only localhost, so until then the linked vulnerabilities do not seem like a considerable threat.

@sj26 sj26 linked a pull request Nov 1, 2021 that will close this issue
@sj26 sj26 closed this as completed Nov 1, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants