FreeBSD Bugzilla – Attachment 220019 Details for
Bug 251418
sysutils/consul: Update to 1.9.0
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
patch
consul.diff (text/plain), 2.35 KB, created by
Brad Davis
on 2020-11-27 02:13:03 UTC
(
hide
)
Description:
patch
Filename:
MIME Type:
Creator:
Brad Davis
Created:
2020-11-27 02:13:03 UTC
Size:
2.35 KB
patch
obsolete
>Index: security/vuxml/vuln.xml >=================================================================== >--- security/vuxml/vuln.xml (revision 556425) >+++ security/vuxml/vuln.xml (working copy) >@@ -58,6 +58,36 @@ > * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) > --> > <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> >+ <vuln vid="8d17229f-3054-11eb-a455-ac1f6b16e566"> >+ <topic>consul -- Fix Consul Connect CA private key configuration</topic> >+ <affects> >+ <package> >+ <name>consul</name> >+ <range><lt>1.9.0</lt></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>Hashicorp reports:</p> >+ <blockquote cite="https://github.com/hashicorp/consul/blob/master/CHANGELOG.md"> >+ <p>Increase the permissions to read from the >+ /connect/ca/configuration endpoint to operator:write. >+ Previously Connect CA configuration, including the private >+ key, set via this endpoint could be read back by an operator >+ with operator:read privileges.</p> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <url>https://github.com/hashicorp/consul/blob/master/CHANGELOG.md</url> >+ <cvename>CVE-2020-28053</cvename> >+ </references> >+ <dates> >+ <discovery>2020-11-02</discovery> >+ <entry>2020-11-27</entry> >+ </dates> >+ </vuln> >+ > <vuln vid="618010ff-3044-11eb-8112-000c292ee6b8"> > <topic>nomad -- multiple vulnerabilities</topic> > <affects> >Index: sysutils/consul/Makefile >=================================================================== >--- sysutils/consul/Makefile (revision 556349) >+++ sysutils/consul/Makefile (working copy) >@@ -1,7 +1,7 @@ > # $FreeBSD$ > > PORTNAME= consul >-PORTVERSION= 1.8.5 >+PORTVERSION= 1.9.0 > DISTVERSIONPREFIX= v > CATEGORIES= sysutils > >Index: sysutils/consul/distinfo >=================================================================== >--- sysutils/consul/distinfo (revision 556349) >+++ sysutils/consul/distinfo (working copy) >@@ -1,3 +1,3 @@ >-TIMESTAMP = 1604417829 >-SHA256 (hashicorp-consul-v1.8.5_GH0.tar.gz) = c5440637f4f9650f6c9ecd2a866bc0fe1648a4594657e5694637cf4667fe8b0f >-SIZE (hashicorp-consul-v1.8.5_GH0.tar.gz) = 28508874 >+TIMESTAMP = 1606441416 >+SHA256 (hashicorp-consul-v1.9.0_GH0.tar.gz) = 62268e6e6ff3381aca0711d29f462e7a787cb333992c1ecbe0e95f15f66f28e1 >+SIZE (hashicorp-consul-v1.9.0_GH0.tar.gz) = 31222935
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 251418
: 220019