Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update ui-classic to match manageiq rails version #7056

Merged
merged 1 commit into from
May 19, 2020

Conversation

jrafanie
Copy link
Member

@jrafanie jrafanie commented May 19, 2020

Note, ui-classic can't run without manageiq but we're updating it to be consistent.

From:
ManageIQ/manageiq#20188

[CVE-2020-8162] Circumvention of file size limits in ActiveStorage
[CVE-2020-8164] Possible Strong Parameters Bypass in ActionPack
[CVE-2020-8165] Potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
[CVE-2020-8166] Ability to forge per-form CSRF tokens given a global CSRF token
[CVE-2020-8167] CSRF Vulnerability in rails-ujs

https://weblog.rubyonrails.org/2020/5/18/Rails-5-2-4-3-and-6-0-3-1-have-been-released/

Note, ui-classic can't run without manageiq but we're updating it to be consistent.

From:
ManageIQ/manageiq#20188

[CVE-2020-8162] Circumvention of file size limits in ActiveStorage
[CVE-2020-8164] Possible Strong Parameters Bypass in ActionPack
[CVE-2020-8165] Potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
[CVE-2020-8166] Ability to forge per-form CSRF tokens given a global CSRF token
[CVE-2020-8167] CSRF Vulnerability in rails-ujs

https://weblog.rubyonrails.org/2020/5/18/Rails-5-2-4-3-and-6-0-3-1-have-been-released/
@jrafanie
Copy link
Member Author

@miq-bot add_label jansa/yes?

@chessbyte chessbyte self-assigned this May 19, 2020
@chessbyte chessbyte merged commit 577f4a2 into ManageIQ:master May 19, 2020
simaishi pushed a commit that referenced this pull request May 21, 2020
Update ui-classic to match manageiq rails version

(cherry picked from commit 577f4a2)
@simaishi
Copy link
Contributor

Jansa backport details:

$ git log -1
commit 1c8dd6ba1ff195bd17f71c9703e431022b4eb1ff
Author: Oleg Barenboim <[email protected]>
Date:   Tue May 19 13:59:04 2020 -0400

    Merge pull request #7056 from jrafanie/bump_to_rails_5_2_4_3

    Update ui-classic to match manageiq rails version

    (cherry picked from commit 577f4a2420113ca7f7ab60e56160ce8ff5c2a27a)

@jrafanie jrafanie deleted the bump_to_rails_5_2_4_3 branch May 5, 2021 22:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants