Project

General

Profile

Actions

Defect #12778

closed

Upgrade to Rails 3.2.11

Added by Raphael Kallensee over 11 years ago. Updated over 11 years ago.

Status:
Closed
Priority:
Urgent
Assignee:
-
Category:
Rails support
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Resolution:
Duplicate
Affected version:

Description

There's a severe vulnerability in all Rails versions. I think it's really important to upgrade Redmine 2.2.0 to Rails 3.2.11 (or push out 2.2.1 soon). I didn't yet check how much Redmine is affected, but the risk seems to be high.

As a quick fix users could upgrade to Rails 3.2.11 manually by changing the version in their Gemfile and do a "bundle update".

An upgrade is also important for the older 2.1.x and 1.4.x versions.

Actions #1

Updated by Etienne Massip over 11 years ago

  • Private changed from No to Yes
Actions #2

Updated by Etienne Massip over 11 years ago

  • Status changed from New to Closed
  • Resolution set to Duplicate
Actions #3

Updated by Raphael Kallensee over 11 years ago

I didn't see any duplicate issue?! But I guess it's there and maybe it's also private?

Actions #4

Updated by Etienne Massip over 11 years ago

Raphael Kallensee wrote:

I didn't see any duplicate issue?! But I guess it's there and maybe it's also private?

Yes, you guess right =)

The first one has been posted about 15 minutes before by a team member with private flag set, otherwise yours would have been the tracked one.

Thanks for the report anyway!

Actions #5

Updated by Etienne Massip over 11 years ago

  • Private changed from Yes to No
Actions

Also available in: Atom PDF