Skip to content

Upgrade Rails to 6.1.4.7#6041

Merged
mitchellhenke merged 1 commit intomainfrom
mitchellhenke/update-rails-patch
Mar 8, 2022
Merged

Upgrade Rails to 6.1.4.7#6041
mitchellhenke merged 1 commit intomainfrom
mitchellhenke/update-rails-patch

Conversation

@mitchellhenke
Copy link
Contributor

We don't appear to be affected based on the description since we don't use Active Storage

The issue impacts applications that use Active Storage with mini_magick as the image_processing back end, and allow untrusted or arbitrary input to control an image’s transformation method.

changelog: Internal, Security, Upgrade Rails to patch vulnerability
Copy link
Contributor

@zachmargolis zachmargolis left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mitchellhenke mitchellhenke merged commit acf42f3 into main Mar 8, 2022
@mitchellhenke mitchellhenke deleted the mitchellhenke/update-rails-patch branch March 8, 2022 20:53
mdiarra3 pushed a commit that referenced this pull request Mar 10, 2022
changelog: Internal, Security, Upgrade Rails to patch vulnerability
@aduth aduth mentioned this pull request Mar 15, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants