CVE-2020-15237: Information Exposure Through Discrepancy
(updated )
In Shrine using Rack::Utils.secure_compare
. Users using the derivation_endpoint
plugin are urged to upgrade to Shrine or greater. A possible workaround is provided in the linked advisory.
References
Detect and mitigate CVE-2020-15237 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →