Project

General

Profile

Refactor #13698

update to rest-client 1.8.x

Added by Anonymous over 4 years ago. Updated about 2 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Packaging
Target version:
Difficulty:
Triaged:
Bugzilla link:
Fixed in Releases:
Found in Releases:

Description

rest-client is pinned to '~> 1.6.0' at the moment, blocking an update to a newer rbovirt. Also 1.6.9 has two security issues which are probably not critical for Foreman core, but won't get resolved in 1.6.x:

Name: rest-client
Version: 1.6.9
Advisory: CVE-2015-1820
Criticality: Unknown
URL: https://github.com/rest-client/rest-client/issues/369
Title: rubygem-rest-client: session fixation vulnerability via Set-Cookie headers in 30x redirection responses
Solution: upgrade to >= 1.8.0

Name: rest-client
Version: 1.6.9
Advisory: CVE-2015-3448
Criticality: Unknown
URL: http://www.osvdb.org/show/osvdb/117461
Title: Rest-Client Gem for Ruby logs password information in plaintext
Solution: upgrade to >= 1.7.3


Related issues

Blocks Foreman - Feature #8289: use cloudinit user data in ovirt/rhev compute ressourceClosed2014-11-05
Blocked by Katello - Refactor #13699: update to rest-client 1.8.xRejected2016-02-14
Blocks Packaging - Feature #14809: Build RPMs for Fedora 24Closed2016-04-26

Associated revisions

Revision 7635745f (diff)
Added by Michael Moll about 4 years ago

fixes #13698 - update rest-client and rbovirt gems

- update rest-client to 1.8.x
- update rbovirt to 0.1.x

Revision 40eacae1 (diff)
Added by Dominic Cleal about 4 years ago

refs #13698 - update rest-client and rbovirt gems

History

#1 Updated by Anonymous over 4 years ago

  • Blocks Feature #8289: use cloudinit user data in ovirt/rhev compute ressource added

#2 Updated by Anonymous over 4 years ago

#3 Updated by The Foreman Bot over 4 years ago

  • Status changed from New to Ready For Testing

#4 Updated by Dominic Cleal over 4 years ago

#5 Updated by Dominic Cleal about 4 years ago

  • Legacy Backlogs Release (now unused) set to 136

#6 Updated by Anonymous about 4 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100

Also available in: Atom PDF