diff --git a/lib/checks/check_escape_function.rb b/lib/checks/check_escape_function.rb index bdca32fb78a788854406f8680770f1cd291fb275..839063ed75f16d2552c705cc9a315b1c85631abc 100644 --- a/lib/checks/check_escape_function.rb +++ b/lib/checks/check_escape_function.rb @@ -7,10 +7,10 @@ class CheckEscapeFunction < BaseCheck Checks.add self def run_check - if version_between?('2.0.0', '2.3.12') and RUBY_VERSION < '1.9.0' + if version_between?('2.0.0', '2.3.13') and RUBY_VERSION < '1.9.0' warn :warning_type => 'Cross Site Scripting', - :message => 'Versions before 2.3.13 have a vulnerability in escape method when used with Ruby 1.8. Upgrade or apply patches as needed.', + :message => 'Versions before 2.3.14 have a vulnerability in escape method when used with Ruby 1.8. Upgrade or apply patches as needed.', :confidence => CONFIDENCE[:high] end end