Bug 205963

Summary: textproc/kibana43: upgrade to version 4.3.1
Product: Ports & Packages Reporter: Jimmy Olgeni <olgeni>
Component: Individual Port(s)Assignee: Jimmy Olgeni <olgeni>
Status: Closed FIXED    
Severity: Affects Only Me CC: junovitch, skozlov
Priority: --- Keywords: patch
Version: LatestFlags: skozlov: maintainer-feedback+
junovitch: merge-quarterly+
Hardware: Any   
OS: Any   
Attachments:
Description Flags
Upgrade patch koobs: maintainer-approval+

Description Jimmy Olgeni freebsd_committer freebsd_triage 2016-01-06 16:44:26 UTC
Created attachment 165164 [details]
Upgrade patch

Upgrade to version 4.3.1.

Poudriere log here:

http://olgeni.olgeni.com/~olgeni/log/kibana43-4.3.1.log
Comment 1 commit-hook freebsd_committer freebsd_triage 2016-01-07 16:10:25 UTC
A commit references this bug:

Author: olgeni
Date: Thu Jan  7 16:09:25 UTC 2016
New revision: 405465
URL: https://svnweb.freebsd.org/changeset/ports/405465

Log:
  Upgrade textproc/kibana43 to version 4.3.1.

  PR:		205963
  Submitted by:	olgeni
  Approved by:	maintainer

Changes:
  head/textproc/kibana43/Makefile
  head/textproc/kibana43/distinfo
  head/textproc/kibana43/pkg-plist
Comment 2 Jimmy Olgeni freebsd_committer freebsd_triage 2016-01-07 16:11:52 UTC
Patch committed.
Comment 3 Jason Unovitch freebsd_committer freebsd_triage 2016-01-08 00:06:09 UTC
Reopen and set merge-quarterly?.  Can this get MFH'd?   See https://www.elastic.co/blog/kibana-4-3-1-and-4-2-2-and-4-1-4 as there is a security issue documented.

4.3.1 Changes
Fixes XSS vulnerability (CVE pending) - Thanks to Vladimir Ivanov for responsibly reporting
Comment 4 Jimmy Olgeni freebsd_committer freebsd_triage 2016-01-08 08:59:28 UTC
https://reviews.freebsd.org/D4831
Comment 5 commit-hook freebsd_committer freebsd_triage 2016-01-13 23:58:11 UTC
A commit references this bug:

Author: junovitch
Date: Wed Jan 13 23:57:53 UTC 2016
New revision: 406081
URL: https://svnweb.freebsd.org/changeset/ports/406081

Log:
  Document Kibana 4.x XSS vulnerabilty

  PR:		205961
  PR:		205962
  PR:		205963
  Security:	https://vuxml.FreeBSD.org/freebsd/a7a4e96c-ba50-11e5-9728-002590263bf5.html

Changes:
  head/security/vuxml/vuln.xml
Comment 6 Jason Unovitch freebsd_committer freebsd_triage 2016-01-14 00:01:09 UTC
Closed PR again and set merge-quartely+... Fix MFH'd in https://svnweb.freebsd.org/changeset/ports/406045