[ubuntu/focal-security] rabbitmq-server 3.8.3-0ubuntu0.2 (Accepted)
Rodrigo Figueiredo Zaiden
rodrigo.zaiden at canonical.com
Mon Dec 9 13:21:28 UTC 2024
rabbitmq-server (3.8.3-0ubuntu0.2) focal-security; urgency=medium
* SECURITY UPDATE: Cross site scripting.
- debian/patches/CVE-2021-32718.patch: Escape html in
res.req_params.username in .../www/js/dispatcher.js.
- debian/patches/CVE-2021-32719.patch: Format
upstream.value['consumer-tag'] in
.../www/js/tmpl/federation-upstream.ejs.
- CVE-2021-32718
- CVE-2021-32719
rabbitmq-server (3.8.3-0ubuntu0.1) focal; urgency=medium
* New upstream verison 3.8.3 (LP: #2060248).
- RabbitMQ nodes will now gracefully shutdown when receiving a `SIGTERM`
signal. Previously the runtime would invoke a default handler that
terminates the VM giving RabbitMQ no chance to execute its shutdown
steps.
- Speedup execution of boot steps by a factor of 2N, where N is the number
of attributes per step.
- New health checks that can be used to determine if it's a good moment to
shut down a node for an upgrade.
- details about these changes can be found at
https://github.com/rabbitmq/rabbitmq-server/blob/main/release-notes/3.8.3.md
* Packaging changes needed by this update:
- d/watch: update to find upstream tarball, and verify its signature
- d/upstream/signing-key.asc: added, downloaded from
https://github.com/rabbitmq/signing-keys/releases/download/3.0/rabbitmq-release-signing-key.asc
- d/p/CVE-2023-46118-{1,2}.patch: refresh
- d/p/lp1999816-fix-rabbitmqctl-status-disk-free-timeout.patch: fix offset
- d/p/lets-use-python3-not-python-binary.patch: refresh
* Added new dep8 tests (LP: #1679386):
- d/t/smoke-test
- d/t/hello-world
- d/t/publish-subscribe
- d/t/rpc
- d/t/work-queue
Date: 2024-12-06 15:10:12.393280+00:00
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
Signed-By: Rodrigo Figueiredo Zaiden <rodrigo.zaiden at canonical.com>
https://launchpad.net/ubuntu/+source/rabbitmq-server/3.8.3-0ubuntu0.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the Focal-changes
mailing list