Skip to content

Commit ec426a0

Browse files
authored
Fix CVE-2023-46118 for rabbitmq-server (#10626)
1 parent 15b043a commit ec426a0

4 files changed

Lines changed: 12 additions & 9 deletions

File tree

SPECS/rabbitmq-server/generate-rabbitmq-server-tarball.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212

1313
# baseline variables for filename and temporary directory to avoid filenme collisions
1414
TEMP_TARBALL_DIR="TempRabbitmqTarball"
15-
VENDOR_TARBALL_NAME="rabbitmq-server-hex-vendor-3.11.11"
15+
VENDOR_TARBALL_NAME="rabbitmq-server-hex-vendor-3.11.24"
1616

1717
#Create Hex Packag arrays and link
1818
HEX_PM_LINK="https://repo.hex.pm/tarballs"
Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
{
22
"Signatures": {
3-
"rabbitmq-server-3.11.11.tar.xz": "0ff32c1b4a5dd28cc8651af28e4a5e7e577bd58119180949d979492b32a90996",
4-
"rabbitmq-server-hex-vendor-3.11.11.tar.gz": "f8176440e667f2cead0221ab139079650adcd916ef37396ff41243536b6b3f70",
53
"mix_task_archive_deps-1.0.0.ez": "e6079c02cbbb41526ea18e8142a14093094c2f1942865f1cb64fbc4eb6212a48",
6-
"rabbitmq-server-hex-cache-3.11.11.tar.gz": "d0e45732afb04dfd3941e8a304dc8b6ff9e5aa73f52c16af2a3f78a967f14708"
4+
"rabbitmq-server-3.11.24.tar.xz": "11090580cb8ffedcf40d1c7c4e3dcccf17658237ca8549f51b057ba9e359ab9b",
5+
"rabbitmq-server-hex-cache-3.11.24.tar.gz": "f3339bb5e3d1577af325799d16cb260dee8b09daf973665951676c6ab0ca0ec4",
6+
"rabbitmq-server-hex-vendor-3.11.24.tar.gz": "f352bbcf85cf696cfda2833aceabdd485ac2e2900e8d4a0ea4d88255d8373252"
77
}
8-
}
8+
}

SPECS/rabbitmq-server/rabbitmq-server.spec

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
%define debug_package %{nil}
22
Summary: rabbitmq-server
33
Name: rabbitmq-server
4-
Version: 3.11.11
5-
Release: 2%{?dist}
4+
Version: 3.11.24
5+
Release: 1%{?dist}
66
License: Apache-2.0 and MPL 2.0
77
Vendor: Microsoft Corporation
88
Distribution: Mariner
@@ -115,6 +115,9 @@ done
115115
%{_libdir}/rabbitmq/lib/rabbitmq_server-%{version}/*
116116

117117
%changelog
118+
* Tue Oct 4 2024 Bhagyashri Pathak <bhapathak@microsoft.com> - 3.11.24-1
119+
- Upgrade version to 3.11.24 to fix CVE-2023-46118
120+
118121
* Wed Jan 17 2024 Harshit Gupta <guptaharshit@microsoft.com> - 3.11.11-2
119122
- Release bump with no changes to force a rebuild and consume new erlang build
120123

cgmanifest.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25414,8 +25414,8 @@
2541425414
"type": "other",
2541525415
"other": {
2541625416
"name": "rabbitmq-server",
25417-
"version": "3.11.11",
25418-
"downloadUrl": "https://github.com/rabbitmq/rabbitmq-server/releases/download/v3.11.11/rabbitmq-server-3.11.11.tar.xz"
25417+
"version": "3.11.24",
25418+
"downloadUrl": "https://github.com/rabbitmq/rabbitmq-server/releases/download/v3.11.24/rabbitmq-server-3.11.24.tar.xz"
2541925419
}
2542025420
}
2542125421
},

0 commit comments

Comments
 (0)