Skip to content

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Nov 11, 2025

Combined/deleted duplicate httparty gem advisory as part of PR#585

In connection with PR#585, merged GHSA-5pq7-52mg-hr42.yml into CVE-2024-22049.yml
then deleted GHSA-5pq7-52mg-hr42.yml as duplicate.

Copy link
Member

@postmodern postmodern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noticed two things that were added, but otherwise approve of the deletion.

- https://github.com/jnunemaker/httparty/security/advisories/GHSA-5pq7-52mg-hr42
- https://github.com/jnunemaker/httparty/commit/cdb45a678c43e44570b4e73f84b1abeb5ec22b8e
- https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
- https://bugzilla.mozilla.org/show_bug.cgi?id=1556711
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How is this link related to httparty? Seems to relate more to Firefox, but does mention Ruby on Rails.

* An attack that rewrites the \"name\" field according to the
crafted file name, impersonating (overwriting) another field.
* Attacks that rewrite the filename extension at the time
multipart/form-datais generated by tampering with the filename.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we really need a separate section for the GHSA version of the description? Might be better to merge the information into the above description text.

@jasnow jasnow closed this Nov 12, 2025
@jasnow jasnow deleted the ghsa-syncbot-2025-11-11-16_22_20 branch November 12, 2025 14:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants