FS#72728 - [redmine] [Security] information disclosure (CVE-2021-42326)

Attached to Project: Community Packages
Opened by loqs (loqs) - Friday, 12 November 2021, 21:51 GMT
Last edited by Sergej Pupykin (sergej) - Saturday, 13 November 2021, 20:12 GMT
Task Type Bug Report
Category Security
Status Closed
Assigned To Sergej Pupykin (sergej)
Levente Polyak (anthraxx)
Architecture All
Severity Medium
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Summary
=======

The package redmine is vulnerable to information disclosure via CVE-2021-42326.

Guidance
========
CVE-2021-42326 is fixed in 4.2.3.
Switch to ruby2.7 now redmine supports it [1]. ruby2.6 can then be dropped as redmine is the last package using it.
Change arch to x86_64 as package ships .so files.
Force all ruby extensions to be built locally to pick up local flags and link to packaged libraries.
Added sqlite3 to Gemfile.local to match optdepends. Remove gems from Gemfile.local that no longer appear to be needed.
Remove extension related build files mkmf.log,gem_make.out and */ext/
PKGBUILD.diff [2] contains the above changes.

References
==========

https://security.archlinux.org/AVG-2462
https://www.redmine.org/projects/redmine/wiki/Security_Advisories
https://www.redmine.org/issues/35789
https://github.com/redmine/redmine/commit/3fd9787e43f7092490e7f0ce36900bbeafd4921b
[1] https://www.redmine.org/issues/31500
[2] PKGBUILD.diff
This task depends upon

Closed by  Sergej Pupykin (sergej)
Saturday, 13 November 2021, 20:12 GMT
Reason for closing:  Fixed
Additional comments about closing:  updated, thank you

Loading...