This repository has been archived by the owner on Apr 17, 2023. It is now read-only.
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
update uglifier gem for fixing a security issue (OSVDB-126747)
It was discovered that the upstream library for uglifier Gem for Ruby, UglifyJS, versions 2.4.23 and earlier, was affected by a vulnerability which allows a specially crafted JavaScript file to have altered functionality after minification. This bug was demonstrated to allow potentially malicious code to be hidden within secure code, activated by minification. References: mishoo/UglifyJS#751 https://zyan.scripts.mit.edu/blog/backdooring-js/
- Loading branch information