Skip to content
Snippets Groups Projects

Update RedCloth to 4.3.2 for CVE-2012-6684

What does this MR do?

To fix XSS (CVE-2012-6684), upgrade RedCloth to 4.3.2.

Are there points in the code the reviewer needs to double check?

No.

Why was this MR needed?

Security vulnerability in RedCloth (CVE-2012-6684) should be fixed to provide GitLab as a secure software.

What are the relevant issue numbers?

Closes #19169 (closed)

cf. !2037 (merged), !2071 (merged)

Does this MR meet the acceptance criteria?

Merge request reports

Loading
Loading

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
  • @stanhu patch release?

  • Stan Hu Milestone changed to %8.9

    Milestone changed to %8.9

  • Stan Hu Added ~149423 label

    Added ~149423 label

  • username-removed-100770 Marked the task Branch has no merge conflicts with master (if you do - rebase it please) as incomplete

    Marked the task Branch has no merge conflicts with master (if you do - rebase it please) as incomplete

  • Added 69 commits:

  • username-removed-100770 Marked the task Branch has no merge conflicts with master (if you do - rebase it please) as completed

    Marked the task Branch has no merge conflicts with master (if you do - rebase it please) as completed

  • @stanhu what is next step here?

  • I think we should target this for 8.9.5. Do we need to backport?

    /cc: @rspeicher

  • @tnir Can you rebase master and bump the CHANGELOG to 8.9.5?

  • OMG finally. :tada:

    I think we should target this for 8.9.5. Do we need to backport?

    @stanhu Agreed about 8.9.5. I'm not too concerned about backporting -- this gem has been vulnerable for as long as I can remember. WDYT?

  • I'm not too concerned about backporting -- this gem has been vulnerable for as long as I can remember. WDYT?

    Sounds good.

  • Added 262 commits:

  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Please register or sign in to reply
    Loading