A ruby-git security update has been released for Debian GNU/Linux 9 Extended LTS to address a couple of vulnerabilities.
ELA-784-1 ruby-git security update
Package : ruby-git
ELA-784-1 ruby-git security update
Version : 1.2.8-1+deb9u1 (stretch)
Related CVEs :
CVE-2022-25648
CVE-2022-46648
CVE-2022-47318
A couple of vulnerabilities were reported against ruby-git, a Ruby interface to the Git revision control system, that could lead to a command injection and execution of an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product.