Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: NixOS/nixpkgs
base: 344652380833
Choose a base ref
...
head repository: NixOS/nixpkgs
compare: 1fb696974478
Choose a head ref
  • 8 commits
  • 7 files changed
  • 4 contributors

Commits on Dec 9, 2020

  1. cassandra: 3.11.4 -> 3.11.9

    Reason: Fixes CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability
    
    Description:
    It is possible for a local attacker without access to the Apache Cassandra
    process or configuration files to manipulate the RMI registry to perform a
    man-in-the-middle attack and capture user names and passwords used to access
    the JMX interface. The attacker can then use these credentials to access
    the JMX interface and perform unauthorised operations.
    
    Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables
    this issue to be exploited remotely.
    
    3.11.x users should upgrade to 3.11.8
    
    (cherry picked from commit 90d2986)
    redvers authored and roberth committed Dec 9, 2020
    Copy the full SHA
    b3af993 View commit details
    Browse the repository at this point in the history
  2. cassandra_2_1: 2.1.20 -> 2.1.22

    Reason: Fixes CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability
    
    Description:
    It is possible for a local attacker without access to the Apache Cassandra
    process or configuration files to manipulate the RMI registry to perform a
    man-in-the-middle attack and capture user names and passwords used to access
    the JMX interface. The attacker can then use these credentials to access
    the JMX interface and perform unauthorised operations.
    
    Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables
    this issue to be exploited remotely.
    
    2.1.x users should upgrade to 2.1.22
    
    (cherry picked from commit b0f1fea)
    redvers authored and roberth committed Dec 9, 2020
    Copy the full SHA
    bbbecfb View commit details
    Browse the repository at this point in the history
  3. cassandra_2_2: 2.2.14 -> 2.2.19

    Reason: Fixes CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability
    
    Description:
    It is possible for a local attacker without access to the Apache Cassandra
    process or configuration files to manipulate the RMI registry to perform a
    man-in-the-middle attack and capture user names and passwords used to access
    the JMX interface. The attacker can then use these credentials to access
    the JMX interface and perform unauthorised operations.
    
    Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables
    this issue to be exploited remotely.
    
    2.2.x users should upgrade to 2.2.18
    
    (cherry picked from commit ee1b13d)
    redvers authored and roberth committed Dec 9, 2020
    Copy the full SHA
    e8a9922 View commit details
    Browse the repository at this point in the history
  4. cassandra_3_0: 3.0.17 -> 3.0.23

    Reason: Fixes CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability
    
    Description:
    It is possible for a local attacker without access to the Apache Cassandra
    process or configuration files to manipulate the RMI registry to perform a
    man-in-the-middle attack and capture user names and passwords used to access
    the JMX interface. The attacker can then use these credentials to access
    the JMX interface and perform unauthorised operations.
    
    Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables
    this issue to be exploited remotely.
    
    3.0.x users should upgrade to 3.0.22
    
    (cherry picked from commit 1431c3c)
    redvers authored and roberth committed Dec 9, 2020
    Copy the full SHA
    3ede26b View commit details
    Browse the repository at this point in the history
  5. cassandra: remove maintainer cransom

    I've been disconnected from Cassandra for years now, I wouldn't be an
    appropriate maintainer.
    
    (cherry picked from commit f6e974e)
    Casey Ransom authored and roberth committed Dec 9, 2020
    Copy the full SHA
    d9bc130 View commit details
    Browse the repository at this point in the history
  6. cassandra: Add passthru.tests

    (cherry picked from commit a298710)
    roberth committed Dec 9, 2020
    Copy the full SHA
    a8ae728 View commit details
    Browse the repository at this point in the history
  7. cassandra: Remove version assertion

    NixOS 20.09 does not support passthru on tests.
    roberth committed Dec 9, 2020
    Copy the full SHA
    eb6b46c View commit details
    Browse the repository at this point in the history

Commits on Dec 10, 2020

  1. Merge pull request #106477 from hercules-ci/cassandra-backports

    [20.09] cassandra backports
    roberth committed Dec 10, 2020
    Copy the full SHA
    1fb6969 View commit details
    Browse the repository at this point in the history