Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

INSUS-233 Upgrade rack version to 2.14 for azure-chef-extension #378

Merged
merged 3 commits into from
Jun 23, 2022

Conversation

RoyShravani
Copy link
Collaborator

Upgrading rack version from 2.0.6 to 2.1.4 to resolve directory traversal vulnerability CVE-2020-8161

Description

INSUS-233 A directory traversal vulnerability exists in rack <2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.

Related Issue

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Chore (non-breaking change that does not add functionality or fix an issue)

Checklist:

  • I have read the CONTRIBUTING document.
  • I have run the pre-merge tests locally and they pass.
  • I have updated the documentation accordingly.
  • I have added tests to cover my changes.
  • All new and existing tests passed.
  • All commits have been signed-off for the Developer Certificate of Origin.

Signed-off-by: Shravani Roy <Shravani.Roy@progress.com>
Signed-off-by: Shravani Roy <Shravani.Roy@progress.com>
@RoyShravani RoyShravani self-assigned this Jun 15, 2022
@saghoshprogress saghoshprogress merged commit a5e57f5 into main Jun 23, 2022
@RoyShravani RoyShravani deleted the INFSUS-233 branch June 24, 2022 06:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants