Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security: Upgrade Rails to 5.2.2.1 #504

Merged
merged 1 commit into from
Mar 13, 2019
Merged

Conversation

Mr0grog
Copy link
Member

@Mr0grog Mr0grog commented Mar 13, 2019

This fixes several vulnerabilities:

For more info, see the release notes: https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/

I’m going to go ahead and merge this shortly so we can get an updated release out.

This fixes several vulnerabilities:

- CVE-2019-5418 File Content Disclosure in Action View
- CVE-2019-5419 Denial of Service Vulnerability in Action View
- CVE-2019-5420 Possible Remote Code Execution Exploit in Rails Development Mode

For more info, see the release notes: https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/
@Mr0grog Mr0grog merged commit 2b622c7 into master Mar 13, 2019
@Mr0grog Mr0grog deleted the security-rails-5.2.2.1 branch March 13, 2019 22:13
Mr0grog added a commit that referenced this pull request Mar 13, 2019
Mr0grog added a commit to edgi-govdata-archiving/web-monitoring-ops that referenced this pull request Mar 13, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant