Uploaded image for project: 'Puppet Agent'
  1. Puppet Agent
  2. PA-4805

Bump puppet-runtime's Ruby to 2.7.7

    XMLWordPrintable

Details

    • Phoenix
    • 2
    • CVE-2021-33621
    • Phoenix 2022-12-07
    • Security Fix
    • Updates puppet-agent's Ruby to 2.7.7, addressing CVE-2021-33621
    • Needs Assessment

    Description

      Ruby 2.7.7 was released on November 24: https://www.ruby-lang.org/en/news/2022/11/24/ruby-2-7-7-released/

      The release addresses a high criticality vulnerability (8.8 CVSS), CVE-2021-33621: https://nvd.nist.gov/vuln/detail/CVE-2021-33621

      We need to bump Ruby 2.7 in our runtimes from 2.7.6 to 2.7.7 and apply any relevant patches to Ruby 2.5.9.

      Attachments

        Activity

          People

            Unassigned Unassigned
            michael.hashizume Michael Hashizume
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Zendesk Support