File rubygem-puppet.changes of Package rubygem-puppet.26170
-------------------------------------------------------------------
Mon Sep 19 10:21:01 UTC 2022 - Danilo Spinella <danilo.spinella@suse.com>
- Fix CVE-2021-27023, unsafe HTTP redirect
(CVE-2021-27023, bsc#1192797)
puppet-4.8.1-CVE-2021-27023.patch
- Refresh puppet-4.8.1-gemspec.patch
-------------------------------------------------------------------
Tue Feb 13 14:02:27 UTC 2018 - kstreitova@suse.com
- add puppet-4.8.1-CVE-2017-10689.patch to reset permissions when
unpacking tar in PMT. When using minitar, files are unpacked with
whatever permissions are in the tarball. This is potentially
unsafe, as tarballs can be easily created with weird permissions
[bsc#1080288], [CVE-2017-10689]
-------------------------------------------------------------------
Mon Jan 23 18:46:56 UTC 2017 - kstreitova@suse.com
- package created (version 4.8.1) [fate#321116]
* provides puppet agent 1.8.1