Package
logstash-9.0
Component
nokogiri
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The nokogiri vulnerability in nokogiri-1.18.10-java.gemspec is fixed in 1.19.3. However, nokogiri 1.19.3 requires Ruby >= 3.2, while logstash-9.0 ships JRuby 9.4 which provides Ruby 3.1.4 compatibility. Bundler refuses to install nokogiri 1.19.3 with this Ruby version. Resolution requires:
Status