Skip to content
Snippets Groups Projects
Commit 773c3a24 authored by Sytse Sijbrandij's avatar Sytse Sijbrandij
Browse files

Merge branch 'CVE-2014-3483' into 'master'

CVE-2014-3483
parents 179cb09e 5867faf2
No related branches found
No related tags found
No related merge requests found
---
layout: post
title: "GitLab not affected by Rails vulnerability CVE-2014-3483"
date: 2014-07-03 13:55
comments: true
categories:
author: Jacob Vosmaer
---
Yesterday the developers of Ruby on Rails released a [security advisory for SQL injection vulnerability CVE-2014-3483](https://groups.google.com/forum/#!topic/rubyonrails-security/wDxePLJGZdI).
GitLab is not affected by this vulnerability.
## Background
CVE-2014-3483 affects applications which use PostgreSQL [bitstring](http://www.postgresql.org/docs/9.2/static/datatype-bit.html) or [range](http://www.postgresql.org/docs/9.2/static/rangetypes.html) types in their database schema.
GitLab uses neither of these types in its database schema.
Please contact us at support@gitlab.com if you have any questions about this issue.
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment