Details
-
Task
-
Status: Resolved
-
Normal
-
Resolution: Fixed
-
None
-
None
-
None
-
Night's Watch
-
2
-
NW - 2021-12-17
-
Bug Fix
-
Patch our vendored Ruby to fix the CVE-2021-41817 vulnerability in the date gem.
-
Needs Assessment
Description
https://www.ruby-lang.org/en/news/2021/11/15/date-parsing-method-regexp-dos-cve-2021-41817/
since ruby 2.5.9 in EOL, we need to perform this manually
Attachments
Issue Links
- blocks
-
PA-4101 Update date gem in puppet AIO packages
-
- Closed
-