Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot - RCE bug with Serialized Columns in Active Record #75

Closed
tuxmea opened this issue Jul 28, 2022 · 3 comments
Closed

Dependabot - RCE bug with Serialized Columns in Active Record #75

tuxmea opened this issue Jul 28, 2022 · 3 comments
Assignees
Labels
bug Something isn't working

Comments

@tuxmea
Copy link
Member

tuxmea commented Jul 28, 2022

https://github.com/betadots/hdm/security/dependabot/77

 Dependabot cannot update activerecord to a non-vulnerable version

The latest possible version that can be installed is 7.0.2.4 because of the following conflicting dependencies:

rails (7.0.2.4) requires activerecord (= 7.0.2.4) via actionmailbox (7.0.2.4)
rails (7.0.2.4) requires activerecord (= 7.0.2.4) via actiontext (7.0.2.4)
rails (7.0.2.4) requires activerecord (= 7.0.2.4) via activestorage (7.0.2.4)
rails (7.0.2.4) requires activerecord (= 7.0.2.4)

The earliest fixed version is 7.0.3.1.
@tuxmea tuxmea added the bug Something isn't working label Jul 28, 2022
@tuxmea
Copy link
Member Author

tuxmea commented Aug 10, 2022

@oneiros Can we update to 7.0.3.x?

@oneiros
Copy link
Collaborator

oneiros commented Aug 10, 2022

@oneiros Can we update to 7.0.3.x?

Absolutely!

FWIW, hdm (OS) is not vulnerable with regards to the RCE bug. But of course it does not hurt to be on the current version.

@rwaffen
Copy link
Member

rwaffen commented Sep 6, 2022

fixed with 9ab0791

@rwaffen rwaffen closed this as completed Sep 6, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants