Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Ruby to 2.6.5 #563

Merged
merged 1 commit into from
Oct 7, 2019
Merged

Update Ruby to 2.6.5 #563

merged 1 commit into from
Oct 7, 2019

Conversation

tas50
Copy link
Contributor

@tas50 tas50 commented Oct 7, 2019

This resolves:

CVE-2019-16255: A code injection vulnerability of Shell#[] and Shell#test
CVE-2019-16254: HTTP response splitting in WEBrick (Additional fix)
CVE-2019-15845: A NUL injection vulnerability of File.fnmatch and File.fnmatch?
CVE-2019-16201: Regular Expression Denial of Service vulnerability of WEBrick’s Digest access authentication

Signed-off-by: Tim Smith tsmith@chef.io

This resolves:

    CVE-2019-16255: A code injection vulnerability of Shell#[] and Shell#test
    CVE-2019-16254: HTTP response splitting in WEBrick (Additional fix)
    CVE-2019-15845: A NUL injection vulnerability of File.fnmatch and File.fnmatch?
    CVE-2019-16201: Regular Expression Denial of Service vulnerability of WEBrick’s Digest access authentication

Signed-off-by: Tim Smith <tsmith@chef.io>
@tas50 tas50 requested review from a team as code owners October 7, 2019 17:57
@tas50 tas50 merged commit 6e2a511 into master Oct 7, 2019
@chef-expeditor chef-expeditor bot deleted the bump-ruby branch October 7, 2019 18:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants