Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

@headius
Copy link
Member

@headius headius commented Jun 30, 2020

This updates our shipped webrick to 1.6.0.

See #6304 for two security spec failures that this addresses.

There seems to be no other released version of webrick that has all the relevant CVE fixes. The versions shipped with CRuby do not correspond to any released version of webrick.

This pulls in nearly all updates including those that resolve
the "request splitting" CVEs.
@headius headius added this to the JRuby 9.2.12.0 milestone Jun 30, 2020
@headius headius merged commit 3b4766d into jruby:jruby-9.2 Jun 30, 2020
@headius headius deleted the update_webrick_1.6.0 branch June 30, 2020 20:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant