This update for rubygem-yard fixes the following issues:
CVE-2017-17042: The server in YARD did not block relative paths with an
initial ../ sequence, which allowed attackers to conduct directory traversal
attacks and read arbitrary files (bsc#1070263).