Skip to content

[pull] master from rubysec:master#105

Open
pull[bot] wants to merge 684 commits intosecurity-geeks:masterfrom
rubysec:master
Open

[pull] master from rubysec:master#105
pull[bot] wants to merge 684 commits intosecurity-geeks:masterfrom
rubysec:master

Conversation

@pull
Copy link

@pull pull bot commented Apr 29, 2021

See Commits and Changes for more details.


Created by pull[bot]

Can you help keep this open source service alive? 💖 Please sponsor : )

@pull pull bot added the ⤵️ pull label Apr 29, 2021
jasnow and others added 29 commits March 13, 2024 17:35
* update to include nokogiri v1.15.6 information (just released)
* add Impact section
* update title to be more accurate and descriptive

Co-authored-by: Postmodern <postmodern.mod3@gmail.com>
---------

Co-authored-by: Postmodern <postmodern.mod3@gmail.com>
---------

Co-authored-by: Postmodern <postmodern.mod3@gmail.com>
* 3.0.1.1 and 3.0.1.2 both belong to the 3.0.1 version family.
* Added `patched_versions` to `gems/katello/CVE-2012-3503.yml`.

  The vulnerability was patched in commit Katello/katello@1fd91b1, which was tagged by the `katello-1.0.6-1` and `katello-1.1.7-1` release tags. However, the first gem version of katello published to https://rubygems.org is 1.5.0. I suspect that prior to the katello-1.5.0 gem, katello was installed directly from git.

---------

Co-authored-by: Postmodern <postmodern.mod3@gmail.com>
---------

Co-authored-by: Postmodern <postmodern.mod3@gmail.com>
---------

Co-authored-by: Postmodern <postmodern.mod3@gmail.com>
jasnow and others added 30 commits January 30, 2026 23:22
---------

Co-authored-by: Postmodern <postmodern.mod3@gmail.com>
---------

Co-authored-by: Postmodern <postmodern.mod3@gmail.com>
* The fix for CVE-2026-25765 was backported to the 1.x version family. See:
  * lostisland/faraday@d0fc049beb
  * GHSA-33mh-2634-fwr2

---------

Co-authored-by: Postmodern <postmodern.mod3@gmail.com>
* Any reviewer comments should go under `notes:`.
---------

Co-authored-by: Postmodern <postmodern.mod3@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.