Updated ruby-rake package fixes security vulnerability:
There is an OS command injection vulnerability in Rake < 12.3.3 in
Rake::FileList when supplying a filename that begins with the pipe
character (CVE-2020-8130).
- https://bugs.mageia.org/show_bug.cgi?id=26266
- https://lists.debian.org/debian-lts-announce/2020/02/msg00026.html
- https://www.cve.org/CVERecord?id=CVE-2020-8130
- 7/core/ruby-rake-12.3.0-21.mga7
Get the latest Linux and open source security news straight to your inbox.