Puppet Dashboard 1.2.19 is now available.

This release of Puppet Dashboard addresses CVE-2013-0155.  All users
are strongly encouraged to update when possible.

This vulnerability exposes ActiveRecord to unsafe query generation.

More information on the vulnerability can be found here:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0155, and in
this post: 
https://groups.google.com/group/rubyonrails-security/browse_thread/thread/73b8d3f8478df5e2

Downloads
========

RPM packages for are available at https://yum.puppetlabs.com/el or /fedora

Debian packages are available at https://apt.puppetlabs.com

Source can be downloaded from
https://puppetlabs.com/downloads/dashboard/puppet-dashboard-1.2.19.tar.gz,
along with the accompanying signature file,
https://puppetlabs.com/downloads/dashboard/puppet-dashboard-1.2.19.tar.gz.asc.

See the Verifying Puppet Download section at:
http://projects.puppetlabs.com/projects/puppet/wiki/Downloading_Puppet

1.2.19 Security Fixes
================
Ernie Miller (1):
      04c1dba Fix for CVE-2013-0155

-- 
You received this message because you are subscribed to the Google Groups 
"Puppet Developers" group.
To post to this group, send email to puppet-dev@googlegroups.com.
To unsubscribe from this group, send email to 
puppet-dev+unsubscr...@googlegroups.com.
For more options, visit this group at 
http://groups.google.com/group/puppet-dev?hl=en.

Reply via email to