MGASA-2021-0124 - Updated ruby-mechanize packages fix a security vulnerability

Publication date: 12 Mar 2021
Type: security
Affected Mageia releases: 7, 8
CVE: CVE-2021-21289

In Mechanize, from v2.0.0 until v2.7.7, there is a command injection
vulnerability. Affected versions of Mechanize allow for OS commands to be
injected using several classes' methods which implicitly use Ruby's Kernel#open
method (CVE-2021-21289).


- 7/core/ruby-mechanize-2.7.6-2.1.mga7
- 8/core/ruby-mechanize-2.7.6-3.1.mga8