diff options
| author | Louise Crow <louise.crow@gmail.com> | 2013-10-24 10:45:21 +0100 |
|---|---|---|
| committer | Louise Crow <louise.crow@gmail.com> | 2013-10-24 10:45:21 +0100 |
| commit | b170c18a5f3a776006649145267724193c54e397 (patch) | |
| tree | 95ee2f51f178185c39bed0df9c25bd08b2e5b628 | |
| parent | 1f6771c1545e320437a2fbecf7ddd0f8abdf77d1 (diff) | |
| parent | d450371502bcd55776e51416afea8741ca66e8b3 (diff) | |
Merge branch 'hotfix/0.14.0.3' into wdtk
| -rw-r--r-- | config/initializers/alaveteli.rb | 1 | ||||
| -rw-r--r-- | lib/actionmailer_patches.rb | 15 |
2 files changed, 16 insertions, 0 deletions
diff --git a/config/initializers/alaveteli.rb b/config/initializers/alaveteli.rb index 8ae78c80c..4041ef7a8 100644 --- a/config/initializers/alaveteli.rb +++ b/config/initializers/alaveteli.rb @@ -50,6 +50,7 @@ require 'normalize_string' require 'alaveteli_file_types' require 'alaveteli_localization' require 'message_prominence' +require 'actionmailer_patches' AlaveteliLocalization.set_locales(AlaveteliConfiguration::available_locales, AlaveteliConfiguration::default_locale) diff --git a/lib/actionmailer_patches.rb b/lib/actionmailer_patches.rb new file mode 100644 index 000000000..600d3c8cc --- /dev/null +++ b/lib/actionmailer_patches.rb @@ -0,0 +1,15 @@ +# Monkey patch for CVE-2013-4389 +# derived from http://seclists.org/oss-sec/2013/q4/118 to fix +# a possible DoS vulnerability in the log subscriber component of +# Action Mailer. + +require 'action_mailer' +module ActionMailer + class LogSubscriber < ActiveSupport::LogSubscriber + def deliver(event) + recipients = Array.wrap(event.payload[:to]).join(', ') + info("\nSent mail to #{recipients} (#{event.duration.round(1)}ms)") + debug(event.payload[:mail]) + end + end +end |
