[ubuntu/focal-security] rabbitmq-server 3.8.3-0ubuntu0.2 (Accepted)

Rodrigo Figueiredo Zaiden rodrigo.zaiden at canonical.com
Mon Dec 9 13:21:28 UTC 2024


rabbitmq-server (3.8.3-0ubuntu0.2) focal-security; urgency=medium

  * SECURITY UPDATE: Cross site scripting.
    - debian/patches/CVE-2021-32718.patch: Escape html in
      res.req_params.username in .../www/js/dispatcher.js.
    - debian/patches/CVE-2021-32719.patch: Format
      upstream.value['consumer-tag'] in
      .../www/js/tmpl/federation-upstream.ejs.
    - CVE-2021-32718
    - CVE-2021-32719

rabbitmq-server (3.8.3-0ubuntu0.1) focal; urgency=medium

  * New upstream verison 3.8.3 (LP: #2060248).
    - RabbitMQ nodes will now gracefully shutdown when receiving a `SIGTERM`
      signal. Previously the runtime would invoke a default handler that
      terminates the VM giving RabbitMQ no chance to execute its shutdown
      steps.
    - Speedup execution of boot steps by a factor of 2N, where N is the number
      of attributes per step.
    - New health checks that can be used to determine if it's a good moment to
      shut down a node for an upgrade.
    - details about these changes can be found at
      https://github.com/rabbitmq/rabbitmq-server/blob/main/release-notes/3.8.3.md
  * Packaging changes needed by this update:
    - d/watch: update to find upstream tarball, and verify its signature
    - d/upstream/signing-key.asc: added, downloaded from
      https://github.com/rabbitmq/signing-keys/releases/download/3.0/rabbitmq-release-signing-key.asc
    - d/p/CVE-2023-46118-{1,2}.patch: refresh
    - d/p/lp1999816-fix-rabbitmqctl-status-disk-free-timeout.patch: fix offset
    - d/p/lets-use-python3-not-python-binary.patch: refresh
  * Added new dep8 tests (LP: #1679386):
    - d/t/smoke-test
    - d/t/hello-world
    - d/t/publish-subscribe
    - d/t/rpc
    - d/t/work-queue

Date: 2024-12-06 15:10:12.393280+00:00
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
Signed-By: Rodrigo Figueiredo Zaiden <rodrigo.zaiden at canonical.com>
https://launchpad.net/ubuntu/+source/rabbitmq-server/3.8.3-0ubuntu0.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Focal-changes mailing list