Use Nokogiri 1.7.2
|Assignee:||Jean-Philippe Lang||% Done:|
Redmine 3.3-stable / 3.2-stable uses Nokogiri 1.6.8 but version from 1.6.8 from 1.7.1 has some security issues (see https://github.com/sparklemotion/nokogiri/blob/master/CHANGELOG.md for details).
Fixed in 1.7.2:
Fixed in 1.7.1:
We should use Nokogiri >= 1.7.2 but unfortunately it requires Ruby >= 2.1.0 (see r16167). The attached patch uses Nokogiri ~> 1.7.2 if RUBY_VERSION >= 2.1.0.
I received this report from Sho Hashimoto.
#3 Updated by Toshi MARUYAMA over 1 year ago
Backport USN-3235-1 to 1.6.8.x stream
#5 Updated by Toshi MARUYAMA over 1 year ago
Nokogiri team refused to maintain old release for old Ruby.
#6 Updated by Holger Just over 1 year ago
In that case, there is not much we can do, besides advising people that it might be a good idea to use a more modern Ruby. People who still require the use of older Rubies (e.g. because they can't or are not allowed to install newer versions) have to deal with the security implications this might bring. They can still use nokogiri 1.6.8 securely if they use a (patched) libxml version from their OS.
As for removing the support for older ruby versions: my comments in #25538 still stand.