Vote #80410
完了Update ruby-openid to 2.9.2
開始日:
2022/05/09
期日:
進捗率:
0%
予定工数:
Redmineorg_URL:
category_id:
45
version_id:
154
issue_org_id:
32294
author_id:
332
assigned_to_id:
1
comments:
2
status_id:
5
tracker_id:
3
plus1:
0
affected_version:
closed_on:
affected_version_id:
説明
We have to update ruby-openid to the latest version because a vulnerability CVE-2019-11027 has been reported. The attached patch updates ruby-openid to 2.9.2.
https://nvd.nist.gov/vuln/detail/CVE-2019-11027
https://github.com/openid/ruby-openid/issues/122
I have confirmed with ruby-openid 2.9.2 that:
- succeeded in signing in to Redmine with "Yahoo OpenID":https://open.login.yahoo.com/
- passes all test with Redmine 3.4-stable, 4.0-stable, and trunk
journals
--------------------------------------------------------------------------------
Committed, thanks.
--------------------------------------------------------------------------------
いいね!0