https://www.ruby-lang.org/en/news/2015/08/18/ruby-2-2-3-released/
本次升级是一个小版本升级,主要解决了一个 RubyGems 2.4.6 相关的安全问题。 根据 Ruby 的版本规则,所有 2.2.x 版本的 Ruby 都推荐升级到最新版本。
We are pleased to announce the release of Ruby 2.2.3. This is a TEENY version release of the stable 2.2 series.
This release includes the security fix for a RubyGems domain name verification vulnerability.
* CVE-2015-3900 Request hijacking vulnerability in RubyGems 2.4.6 and earlier
There are also some bugfixes. See ChangeLog for details.
关于 CVE-2015-3900 Request hijacking vulnerability in RubyGems 2.4.6 and earlier