Changelog for
ruby2.5-rubygem-activestorage-doc-5.2-5.2.2-9.1.x86_64.rpm :
Sat Dec 8 13:00:00 2018 Stephan Kulow
- updated to version 5.2.2
see installed CHANGELOG.md
[#]# Rails 5.2.2 (December 04, 2018) ##
* Support multiple submit buttons in Active Storage forms.
* Chrıs Seelus
*
* Fix `ArgumentError` when uploading to amazon s3
* Hiroki Sanpei
*
* Add a foreign-key constraint to the `active_storage_attachments` table for blobs.
* George Claghorn
*
* Discard `ActiveStorage::PurgeJobs` for missing blobs.
* George Claghorn
*
* Fix uploading Tempfiles to Azure Storage.
* George Claghorn
*
Mon Dec 3 13:00:00 2018 mschnitzerAATTsuse.com
- updated to version 5.2.1.1 (boo#1118076)
- addresses a security vulnerability (CVE-2018-16477, boo#1117641)
Signed download URLs generated by `ActiveStorage` for Google Cloud Storage
service and Disk service include `content-disposition` and `content-type`
parameters that an attacker can modify. This can be used to upload specially
crafted HTML files and have them served and executed inline. Combined with
other techniques such as cookie bombing and specially crafted AppCache
manifests,
an attacker can gain access to private signed URLs within a specific
storage path.
Vulnerable apps are those using either GCS or the Disk service in
production.
Other storage services such as S3 or Azure aren\'t affected.
All users running an affected release should either upgrade or use one of
the
workarounds immediately. For those using GCS, it\'s also recommended to run
the
following to update existing blobs:
```
ActiveStorage::Blob.find_each do |blob|
blob.send :update_service_metadata
end
```
Wed Aug 8 14:00:00 2018 mschnitzerAATTsuse.com
- updated to version 5.2.1 (boo#1104209)
* Fix direct upload with zero-byte files.
(George Claghorn)
* Exclude JSON root from `active_storage/direct_uploads#create` response.
(Javan Makhmali)
Mon Apr 16 14:00:00 2018 mschnitzerAATTsuse.com
- initialize package
see changelog: https://github.com/rails/rails/blob/v5.2.0/activestorage/CHANGELOG.md