-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 14 Dec 2025 19:33:31 +0530 Source: ruby-sidekiq Built-For-Profiles: noudeb Architecture: source Version: 6.0.4+dfsg-2+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@lists.alioth.debian.org> Changed-By: Utkarsh Gupta <utkarsh@debian.org> Closes: 987354 1004193 Changes: ruby-sidekiq (6.0.4+dfsg-2+deb11u1) bullseye-security; urgency=high . * Non-maintainer upload by the LTS team. * Add pessimistic regexp on queue name input to avoid XSS. (Fixes: CVE-2021-30151) (Closes: #987354) * Add patch to validate days parameter to avoid possible DoS in Web UI. (Fixes: CVE-2022-23837) (Closes: #1004193) Checksums-Sha1: 8df8c6b6454774863da75f5b89abdf0eb0772639 2583 ruby-sidekiq_6.0.4+dfsg-2+deb11u1.dsc 75c82b95a88c92b7b0a1c05fa561271c7d3f7c7f 136664 ruby-sidekiq_6.0.4+dfsg.orig.tar.xz e17781b56cb39f7fb57260f837be5ab5d49f44cb 5504 ruby-sidekiq_6.0.4+dfsg-2+deb11u1.debian.tar.xz 8d9e123594ea8876a4256faf0e4798a819d270fb 17035 ruby-sidekiq_6.0.4+dfsg-2+deb11u1_source.buildinfo Checksums-Sha256: 85b4dfe4b51e9a943e1ba4beeb5ced0adb71024480e502c9c1ff862bc567485b 2583 ruby-sidekiq_6.0.4+dfsg-2+deb11u1.dsc fcc67230e097e1ada9348f0ef7817fbf5aff7b2d4b1f4c8d4abf5b66a94ca5ec 136664 ruby-sidekiq_6.0.4+dfsg.orig.tar.xz dc771f1340d5be1f38845cf0174e527da6b25813fbbf383f3a5d5f79e2dcaa21 5504 ruby-sidekiq_6.0.4+dfsg-2+deb11u1.debian.tar.xz f8d4d5ee519dd94104c8c2366332718802d9e787687feab45d52eb6a8c09e2b6 17035 ruby-sidekiq_6.0.4+dfsg-2+deb11u1_source.buildinfo Files: e674cc4e2981495a33be2db71b1f6a66 2583 ruby optional ruby-sidekiq_6.0.4+dfsg-2+deb11u1.dsc 727a2616f418b5b4546c3832489b9686 136664 ruby optional ruby-sidekiq_6.0.4+dfsg.orig.tar.xz cdce690bf63832c8c5e78d5b36d4357a 5504 ruby optional ruby-sidekiq_6.0.4+dfsg-2+deb11u1.debian.tar.xz b1f5e118a5270fa7da494403b39148c1 17035 ruby optional ruby-sidekiq_6.0.4+dfsg-2+deb11u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJHBAEBCgAxFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmk+yp0THHV0a2Fyc2hA ZGViaWFuLm9yZwAKCRCCPpZ2BsNLllOMEACht7mAPuV8kVixbmBOKkeM1tdsjI93 Eejdm0Iu9EIuGM4/iv1f6arB7iYyAxOyMggXsiq8iiEc4t4go3L7AYqgs8m9aBoe AdBCIegKaJL1iU31BF3LdFe7blysUebqVxNY5lcRKtan7cZPpmiurHyg0JAGv8Jh rs+p3eu5+K2WBl0v+GdRD6oE000gJgwbsGv+4uySZ+tKLyKJwAJ3otYTMT7J8i4e VS9wQtfdkjfRTIzaIOwaSHRVi1pYqPN7duYQ4irTtqChO4MXc8SxRodW3m7tYYEp E6/kvdMvkI/ktmnUaWk2v3KuCK55bg+OOAWSGbwlMeU4oFtW+p/jHobJC9hyBCX8 7vvRQY2CgakHaQpDZjle3qZ2q/7ODCGlgsKPaNhEdejx/y6naBa3wSM1M9lJz3gp WmV2abJStepPLSdhHssXSDhBCdDUfN8IWt7M2JDmrfQRzjHX7nhgP5W2DUL5QfSJ dwMjXJM7uT6EcmsSlESmg1ccnAd558a9YXNC+KRr/o1oP1LpJQusHQ0WEmdLk+HI AkaU2mMbzcRuBTBR9p1ZABN9NY2XtcbeOb3uoyk98BTgeML3YBKSecUbLPdGPEg8 a0SlQvlZ3zIXsCRLfDaO+BJ9++OTMQ2jA9456guT0wdk6HDtySyn8ALF4/EmSOG9 r7JUQuihjTZN9A== =WoEU -----END PGP SIGNATURE-----