diff --git a/debian/patches/cve-2017-0882.patch b/debian/patches/cve-2017-0882.patch new file mode 100644 index 0000000000..8b9ed4f69c --- /dev/null +++ b/debian/patches/cve-2017-0882.patch @@ -0,0 +1,28 @@ +Description: Security patch for CVE-2017-0882 +Author: Brian Neel +Bug: https://gitlab.com/gitlab-org/gitlab-ce/issues/29661 +Last-Update: 2017-03-21 +--- +This patch header follows DEP-3: http://dep.debian.net/deps/dep3/ +--- a/app/controllers/projects/issues_controller.rb ++++ b/app/controllers/projects/issues_controller.rb +@@ -112,7 +112,7 @@ + end + + format.json do +- render json: @issue.to_json(include: { milestone: {}, assignee: { methods: :avatar_url }, labels: { methods: :text_color } }) ++ render json: @issue.to_json(include: { milestone: {}, assignee: { only: [:name, :username], methods: [:avatar_url] }, labels: { methods: :text_color } }, methods: [:task_status, :task_status_short]) + end + end + +--- a/app/controllers/projects/merge_requests_controller.rb ++++ b/app/controllers/projects/merge_requests_controller.rb +@@ -278,7 +278,7 @@ + @merge_request.target_project, @merge_request]) + end + format.json do +- render json: @merge_request.to_json(include: { milestone: {}, assignee: { methods: :avatar_url }, labels: { methods: :text_color } }) ++ render json: @merge_request.to_json(include: { milestone: {}, assignee: { only: [:name, :username], methods: [:avatar_url] }, labels: { methods: :text_color } }, methods: [:task_status, :task_status_short]) + end + end + else diff --git a/debian/patches/series b/debian/patches/series index 070c46fd79..d8465521c2 100644 --- a/debian/patches/series +++ b/debian/patches/series @@ -9,3 +9,4 @@ pid-log-paths.patch 0200-remove-order-dependency-in-label-finder-spec.patch 0210-use-jquery-ui-rails6.patch 0300-git-2-11-support.patch +cve-2017-0882.patch