Debian alert DLA-3989-1 (ruby-doorkeeper)
| From: | Adrian Bunk <bunk@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 3989-1] ruby-doorkeeper security update | |
| Date: | Mon, 09 Dec 2024 05:09:14 +0200 | |
| Message-ID: | <Z1ZfWuXY2NrwSzfh@localhost> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3989-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Adrian Bunk December 09, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : ruby-doorkeeper Version : 5.3.0-2+deb11u1 CVE ID : CVE-2023-34246 Debian Bug : 1038950 Improper Authentication has been fixed in ruby-doorkeeper, an OAuth 2 provider for Rails and Grape. For Debian 11 bullseye, this problem has been fixed in version 5.3.0-2+deb11u1. We recommend that you upgrade your ruby-doorkeeper packages. For the detailed security status of ruby-doorkeeper please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ruby-doorkeeper Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmdWX1oACgkQiNJCh6LY mLGl+BAApWoz33xadQZ2AWaZyMKG8TVAC55xKnolN6UoqMSdTyCTYEtYLGOPeANk m42drK+ZTTj3eCns+1uEhTZa81YoNrTI/TKXQu57JuTwaERJwfFNl8o/QbS31cNV xuIGSxs4qvFWYtqQoYV0Os8vyl3C4lNjEGZJqxcKny1CSWyjgR5YVK3waXvtAWr3 IXd6bztyhLWC6jVSuhjUzGkbWqrHI6caT0Y4CvFbny+fs5waqiOBftk1HYGjF1fe 0fIqFEs/QmGx74sCS01CSdvTcKHKlvgfwozJ061GxEhKLyNjzRPf+gayUixlE/hg JKfJ2q9xuRxoQld9L8JpdTUz4BIV4dSp+A5qvkF1VNtYgltLbFsNF1s/h5mFewIv D9ro3OZ0MNb+s0aecVOqqSTsPCLvbIGMN/4uwIS7gBJdf1VBHo/y/j02mPZ8CCBL 16jbu9XI5RbfqHSpvewb2WCdstBwTAip6zM/z3JBpC8Iw+7f7alZIcu32jwgh5wR TOVmcB9GFHLFFyAg1Fc6i0JWSvFH8KW+QyWmS8E7aygBNBZ6oKegSOX17znb3U1A eAxiUv8QBVX2WIfX2/6ZB6GlPyk9RF1GjRALZXTTX+Tfzx5n/OonFOc1pVROGAlG wntA08zMMOevz0GRdKCqNqpID60MXgOL/AilN7V2iQg7iE8ZOAM= =A8xa -----END PGP SIGNATURE-----
