Major vulnerability fix for Rebar3

Fred Hebert <[email protected]>
Newsgroups gmane.comp.lang.erlang.general
Message-ID <CAFA3VZJi_epHZKa=Ep7hUVvXCysQqmc3G9dUuQi_NG4v5jTGHA@mail.gmail.com>
Bad news. You *have* to upgrade Rebar3. We just noticed that SSL validation
had been partially disabled for *years*.

I've written up all the details at
https://ferd.ca/you-ve-got-to-upgrade-rebar3.html

but the TL:DR; is:

- Rebar3 didn't properly check TLS certs for hex packages since version
3.7.0
- Non-hex dependencies are fine
- We don't think there's anybody exploiting it in the wild and it should be
rather difficult
- I've had time to cut releases for OTP-19 to 24 (two releases) and nightly
builds are up to date
- Older versions than 3.14 on OTP prior to 19 have no clear update path
without someone having time to backport the patch further in the past.

Sorry about that.
- Fred.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.