Skip to content

sec: CVE 2024-49761 update rexml to 3.3.9#42

Merged
SimonHoenscheid merged 1 commit intoOpenVoxProject:mainfrom
xyntion:sec-cve-2024-49761-rexml-upgrade
Jul 21, 2025
Merged

sec: CVE 2024-49761 update rexml to 3.3.9#42
SimonHoenscheid merged 1 commit intoOpenVoxProject:mainfrom
xyntion:sec-cve-2024-49761-rexml-upgrade

Conversation

@SimonHoenscheid
Copy link
Copy Markdown
Contributor

@SimonHoenscheid SimonHoenscheid commented Jul 16, 2025

@bastelfreak
Copy link
Copy Markdown
Contributor

Hi, thanks for the PR! I would first like to finish #35, so we can test other PRs better.

@rwaffen
Copy link
Copy Markdown
Member

rwaffen commented Jul 16, 2025

okay, then lets wait for the ci

@bastelfreak
Copy link
Copy Markdown
Contributor

@SimonHoenscheid can you please rebase?

@bastelfreak
Copy link
Copy Markdown
Contributor

@SimonHoenscheid is there a reason why you went for 3.3.9 and not 3.4.1?

@SimonHoenscheid
Copy link
Copy Markdown
Contributor Author

SimonHoenscheid commented Jul 19, 2025

@bastelfreak 3.3.9 is from the puppet-core changelog and I thought there might be a reason they did not go for 3.4.1.
Do you want me to bump to 3.4.1 instead?

@SimonHoenscheid SimonHoenscheid force-pushed the sec-cve-2024-49761-rexml-upgrade branch from f05ddf9 to 6ff70b2 Compare July 19, 2025 07:40
@SimonHoenscheid SimonHoenscheid force-pushed the sec-cve-2024-49761-rexml-upgrade branch from 6ff70b2 to d3b6436 Compare July 20, 2025 13:35
@SimonHoenscheid SimonHoenscheid added the security Related to a security issue label Jul 21, 2025
Copy link
Copy Markdown
Contributor

@bastelfreak bastelfreak left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I assume this doesn't need too much testing because perforce ships the same version

@SimonHoenscheid SimonHoenscheid merged commit 1c5aa8c into OpenVoxProject:main Jul 21, 2025
38 of 40 checks passed
@SimonHoenscheid SimonHoenscheid deleted the sec-cve-2024-49761-rexml-upgrade branch July 21, 2025 11:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Related to a security issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants