-
-
Notifications
You must be signed in to change notification settings - Fork 220
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Incorrect vulnerable versions for passenger vuln #151
Comments
Testing with rubygems,
|
From #rubygems:
Confirmed that |
mveytsman
added a commit
that referenced
this issue
Jul 28, 2015
This issue was "fixed" under the OSVDB renaming PR: |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
This vulnerability
https://github.com/rubysec/ruby-advisory-db/blob/master/gems/passenger/OSVDB-90738.yml
affects versions 4.0.0.beta1 and 4.0.0.beta2 ( see http://old.blog.phusion.nl/2013/03/05/phusion-passenger-4-0-beta-1-and-2-arbitrary-file-deletion-vulnerability/)
The current patched_versions and unaffected_versions don't cover that.
Is it possible to write the conditions that will capture this vuln using only patched_versions and unaffected_versions, or do we need to add a vulnerable_versions field?
(cc @postmodern I ran some test cases with bundler_audit and it fails as well).
The text was updated successfully, but these errors were encountered: