• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

ManageIQ / manageiq / 38676 / 1
49%
master: 63%

Build:
Build:
LAST BUILD BRANCH: kasparov
DEFAULT BRANCH: master
Ran 19 Aug 2016 04:49PM UTC
Files 2482
Run time 98min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

10 Aug 2016 09:25PM UTC coverage: 57.332% (+0.006%) from 57.326%
2.2.5, TEST_SUITE=vmdb

push

travis-ci

root
Merge branch 'fix_expr_cve' into '5.6.z'

Filter input from custom searches

In custom built searches it's possible to submit unfiltered string values into fields that expect integers. These values make their way through `eval` allowing for arbitrary Ruby code execution.

Addresses CVE-2016-5383 and
https://bugzilla.redhat.com/show_bug.cgi?id=1353722

Discovered while investigating this BZ:
https://bugzilla.redhat.com/show_bug.cgi?id=1349429

Thanks to @twade (Tim Wade)

/cc @obarenbo @jfrey

See merge request !1024

73781 of 128691 relevant lines covered (57.33%)

244.54 hits per line

Source Files on job 38676.1 (2.2.5, TEST_SUITE=vmdb)
  • Tree
  • List 0
  • Changed 65
  • Source Changed 1
  • Coverage Changed 65
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Build 38676
  • Travis Job 38676.1
  • 8ba817b4 on github
  • Prev Job for 2.2.5, TEST_SUITE=vmdb on darga (#37849.1)
  • Next Job for 2.2.5, TEST_SUITE=vmdb on darga (#38678.1)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc