Ruby: 2.6.10 → 2.7.7
Ruby · upgrade impact · Official site ↗
Fixed by upgrading to 2.7.7 iVulnerabilities that affect 2.6.10 but no longer affect 2.7.7 — the security gain from this upgrade, by exploited status then exploitation probability.
Exploited first, then by exploitation probability (EPSS).
CVE-2021-28966 HIGH EPSS 0% ✓ cleared in 2.7.7Still open in 2.7.7 iKnown vulnerabilities that affect 2.7.7 too — upgrading to it does not clear these.
These affect 2.7.7 as well — a later release may be needed.
CVE-2023-28756 MEDIUM EPSS 1% → see advisory