1
0
mirror of https://github.com/LaCasemate/fab-manager.git synced 2025-01-29 18:52:22 +01:00

[security] fix for CVE-2015-3224

This commit is contained in:
Sylvain 2017-12-13 15:28:57 +01:00
parent e091b81187
commit 6539c60a14
3 changed files with 6 additions and 5 deletions

View File

@ -8,6 +8,7 @@
- Fix nginx configuration to allow initial Let's Encrypt configuration (#92)
- Events: open api and monitor improvement (#79)
- Fix a bug: refund an invoice with a subscription and disabling it a the same time cause the resulting PDF to display the wrong dates
- Fix a security issue: in development environments, web-console has a vulnerability as described in CVE-2015-3224
- Fixed deploy instructions with docker-compose
## v2.6.0 2017 November 13

View File

@ -30,7 +30,7 @@ group :development, :test do
# gem 'byebug'
# Access an IRB console on exception pages or by using <%= console %> in views
gem 'web-console', '~> 2.0'
gem 'web-console', '~> 2.1.3'
# Spring speeds up development by keeping your application running in the background. Read more: https://github.com/rails/spring
gem 'spring'

View File

@ -70,7 +70,7 @@ GEM
axlsx (>= 2.0.1)
rails (>= 3.1)
bcrypt (3.1.10)
binding_of_caller (0.7.2)
binding_of_caller (0.7.3)
debug_inspector (>= 0.0.1)
bootstrap-sass (3.3.4.1)
autoprefixer-rails (>= 5.0.0.1)
@ -138,7 +138,7 @@ GEM
crass (1.0.2)
daemons (1.2.4)
database_cleaner (1.4.1)
debug_inspector (0.0.2)
debug_inspector (0.0.3)
descendants_tracker (0.0.4)
thread_safe (~> 0.3, >= 0.3.1)
devise (3.4.1)
@ -479,7 +479,7 @@ GEM
equalizer (~> 0.0, >= 0.0.9)
warden (1.2.3)
rack (>= 1.0)
web-console (2.1.2)
web-console (2.1.3)
activemodel (>= 4.0)
binding_of_caller (>= 0.7.2)
railties (>= 4.0)
@ -567,7 +567,7 @@ DEPENDENCIES
uglifier (>= 1.3.0)
unicorn
vcr
web-console (~> 2.0)
web-console (~> 2.1.3)
webmock
BUNDLED WITH