supervisor: security bump to version 3.1.4
authorPeter Korsgaard <peter@korsgaard.com>
Thu, 7 Sep 2017 09:44:59 +0000 (11:44 +0200)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Sat, 9 Sep 2017 20:49:12 +0000 (22:49 +0200)
commit38a1c4821a163f932793a96e036f8fe451398506
tree44b5106fa8e98e94d579d3f7bc41acc3addf4a39
parent0e5448af5091ee208fdd38a4e221f444085dd0c8
supervisor: security bump to version 3.1.4

Fixes CVE-2017-11610 - The XML-RPC server in supervisor before 3.0.1, 3.1.x
before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote
authenticated users to execute arbitrary commands via a crafted XML-RPC
request, related to nested supervisord namespace lookups.

For more details, see
https://github.com/Supervisor/supervisor/issues/964

While we're at it, add hashes for the license files.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/supervisor/supervisor.hash
package/supervisor/supervisor.mk