Debian Package Tracker
Register | Log in
Subscribe

ruby-faye-websocket

Standards-compliant WebSocket client and server

Choose email to subscribe with

general
  • source: ruby-faye-websocket (main)
  • version: 0.11.0-1
  • maintainer: Debian Ruby Team (archive) (DMD)
  • uploaders: Utkarsh Gupta [DMD]
  • arch: all
  • std-ver: 4.5.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 0.10.7-1
  • testing: 0.11.0-1
  • unstable: 0.11.0-1
versioned links
  • 0.10.7-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.11.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ruby-faye-websocket
action needed
1 low-priority security issue in buster low

There is 1 open security issue in buster.

1 issue left for the package maintainer to handle:
  • CVE-2020-15133: (needs triaging) In faye-websocket before version 0.11.0, there is a lack of certification validation in TLS handshakes. The `Faye::WebSocket::Client` class uses the `EM::Connection#start_tls` method in EventMachine to implement the TLS handshake whenever a `wss:` URL is used for the connection. This method does not implement certificate verification by default, meaning that it does not check that the server presents a valid and trusted TLS certificate for the expected hostname. That means that any `wss:` connection made using this library is vulnerable to a man-in-the-middle attack, since it does not confirm the identity of the server it is connected to. For further background information on this issue, please see the referenced GitHub Advisory. Upgrading `faye-websocket` to v0.11.0 is recommended.

You can find information about how to handle this issue in the security team's documentation.

Created: 2021-02-19 Last update: 2021-03-21 19:04
news
[rss feed]
  • [2021-01-07] ruby-faye-websocket 0.11.0-1 MIGRATED to testing (Debian testing watch)
  • [2021-01-02] Accepted ruby-faye-websocket 0.11.0-1 (source) into unstable (Utkarsh Gupta)
  • [2020-12-29] Accepted ruby-faye-websocket 0.10.7-1.1 (source) into unstable (Holger Levsen)
  • [2019-02-07] ruby-faye-websocket 0.10.7-1 MIGRATED to testing (Debian testing watch)
  • [2019-02-04] Accepted ruby-faye-websocket 0.10.7-1 (source all) into unstable, unstable (Utkarsh Gupta) (signed by: Praveen Arimbrathodiyil)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, clang, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.11.0-1

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing