-
Thu Aug 25 2016 Jun Aruga <jaruga@redhat.com> - 1:4.0.2-8
- Fix CVE-2016-6316 cross-site scripting flaw in Action View
Resolves: rhbz#1365008
-
Tue Mar 08 2016 Vít Ondruch <vondruch@redhat.com> - 1:4.0.2-7
- Update the CVE-2016-2097 patch to the latest upstream version.
Related: CVE-2016-2097
- Update the CVE-2016-2098 patch to the latest upstream version.
Related: CVE-2016-2098
-
Wed Feb 24 2016 Vít Ondruch <vondruch@redhat.com> - 1:4.1.5-6
- Fix Directory traversal and information leak in Action View.
Resolves: CVE-2016-2097
- Fix code injection vulnerability.
Resolves: CVE-2016-2098
-
Tue Feb 23 2016 Vít Ondruch <vondruch@redhat.com> - 1:4.1.5-5
- Fix Timing attack vulnerability in Action Controller.
Resolves: CVE-2015-7576
- Fix Possible Object Leak and Denial of Service attack.
Resolves: CVE-2016-0751
- Fix Possible Information Leak Vulnerability.
Resolves: CVE-2016-0752
- Fix Object leak vulnerability for wildcard controller routes.
Resolves: CVE-2015-7581
-
Wed May 07 2014 Josef Stribny <jstribny@redhat.com> - 1:4.0.2-4
- Fix for CVE-2014-0130
- Resolves: rhbz#1095172
-
Tue Feb 18 2014 Josef Stribny <jstribny@redhat.com> - 1:4.0.2-3
- Fixes for CVE-2014-0081
- Resolves: rhbz#1065587
-
Mon Feb 17 2014 Josef Stribny <jstribny@redhat.com> - 1:4.0.2-2
- Depend on scldevel(v8) virtual provide
-
Wed Dec 04 2013 Josef Stribny <jstribny@redhat.com> - 1:4.0.2-1
- Update to ActionPack 4.0.2
- Resolves: rhbz#1037985
- Fix CVE-2013-6417, CVE-2013-6414, CVE-2013-6415, CVE-2013-6416 and CVE-2013-4491
- Resolves: rhbz#1036421
-
Thu Nov 21 2013 Josef Stribny <jstribny@redhat.com> - 1:4.0.1-1
- Update to ActionPack 4.0.1
-
Wed Oct 16 2013 Josef Stribny <jstribny@redhat.com> - 1:4.0.0-2
- Convert to scl