Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bump reabr3 to version 3.20.0 #716

Closed
wants to merge 1 commit into from
Closed

Conversation

lafirest
Copy link

Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification(CVE-2020-13802)

Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification(CVE-2020-13802)
@zmstone
Copy link

zmstone commented Mar 24, 2023

or is it really necessary to commit a rebar3 binary in git repo at all?

@benoitc
Copy link
Owner

benoitc commented Mar 24, 2023

Embedded rebar3 is normally only used for the CI normally. The issue is that new rebar3 bin doesn't support all versions of erlang. It's planned to update it for the newt release.

Can anyone point me to the commit that fixed this "issue" in rebar3 ?

@benoitc
Copy link
Owner

benoitc commented Oct 9, 2023

not needed anymore : bbe73c8

@benoitc benoitc closed this Oct 9, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants