Moses Mendoza | 14 Jun 2012 01:52

Announce: Puppet Dashboard 1.2.9 Available

This is a maintenance and security release of Puppet Dashboard.
It includes contributions from Erik Dalén, Matthaus Litteken, and
Aaron Patterson.

Security content includes a patch to address CVE-2012-2695,
SQL Injection Vulnerability in Ruby on Rails.

This release is available for download at:
https://downloads.puppetlabs.com/dashboard/puppet-dashboard-1.2.9.tar.gz

Debian packages are available at
https://apt.puppetlabs.com

RPM packages are available at

See the Verifying Puppet Download section at:

Please report feedback via the Puppet Labs Redmine site, using an
affected version of 1.2.9:

Documentation is available at:

1.2.9 Security Fixes
===
Patch to Address SQL Injection Vulnerability in Ruby on Rails

    There is a SQL injection vulnerability in Active Record, in ALL
    versions. This vulnerability has been assigned the CVE identifier 
    CVE-2012-2695. Patch content from Aaron Patterson. Additional
    information available here:
    CVE Link:

1.2.9 Bug Fixes
===
*Fix the node:classes rake task
    
    Wrong variable name was used so it always exited with NameError

1.2.9 Changelog
===
Erik Dalén (1)
    d114b09 Fix the node:classes rake task
Matthaus Litteken (1)
    8fed1f8 Update contributors in readme
Aaron Patterson (1)
    1c7437 Patch activerecord for CVE-2012-2695

--
You received this message because you are subscribed to the Google Groups "Puppet Developers" group.
To post to this group, send email to puppet-dev <at> googlegroups.com.
To unsubscribe from this group, send email to puppet-dev+unsubscribe <at> googlegroups.com.
For more options, visit this group at http://groups.google.com/group/puppet-dev?hl=en.

Gmane