Created attachment 165163 [details] Upgrade patch Upgrade to version 4.2.2. Poudriere log here: http://olgeni.olgeni.com/~olgeni/log/kibana42-4.2.2.log
A commit references this bug: Author: olgeni Date: Thu Jan 7 16:09:04 UTC 2016 New revision: 405464 URL: https://svnweb.freebsd.org/changeset/ports/405464 Log: Upgrade textproc/kibana42 to version 4.2.2. PR: 205962 Submitted by: olgeni Approved by: maintainer Changes: head/textproc/kibana42/Makefile head/textproc/kibana42/distinfo head/textproc/kibana42/pkg-plist
Patch committed.
Reopen and set merge-quarterly?. Can this get MFH'd? See https://www.elastic.co/blog/kibana-4-3-1-and-4-2-2-and-4-1-4 as there is a security issue documented. 4.2.2 Changes Fixes XSS vulnerability (CVE pending) - Thanks to Vladimir Ivanov for responsibly reporting
https://reviews.freebsd.org/D4830
A commit references this bug: Author: junovitch Date: Wed Jan 13 23:57:53 UTC 2016 New revision: 406081 URL: https://svnweb.freebsd.org/changeset/ports/406081 Log: Document Kibana 4.x XSS vulnerabilty PR: 205961 PR: 205962 PR: 205963 Security: https://vuxml.FreeBSD.org/freebsd/a7a4e96c-ba50-11e5-9728-002590263bf5.html Changes: head/security/vuxml/vuln.xml
Closed PR again and set merge-quartely+... Fix MFH'd in https://svnweb.freebsd.org/changeset/ports/406044