octoprint: apply patch for CVE-2024-28237

The 1.10.0 upgrade from #306861 seems to be too big to
be safely backported.

I also did not backport CVE-2024-23637: it is split across
a series of patches and impacts quite sensitive parts of OctoPrint.
I am not feeling confident enough to backport it and exploiting the issue
requires an admin level access.
This commit is contained in:
Thomas Gerbet
2024-04-27 14:47:20 +02:00
parent 41ea4d332a
commit 887d63ed7d

View File

@@ -4,6 +4,7 @@
, lib
, fetchFromGitHub
, fetchPypi
, fetchpatch
, python3
, substituteAll
, nix-update-script
@@ -188,6 +189,13 @@ let
src = ./ffmpeg-path.patch;
ffmpeg = "${pkgs.ffmpeg}/bin/ffmpeg";
})
(fetchpatch {
# https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-x7mf-wrh9-r76c
name = "CVE-2024-28237.patch";
url = "https://github.com/OctoPrint/OctoPrint/commit/779894c1bc6478332d14bc9ed1006df1354eb517.patch";
hash = "sha256-JtZSEbzkvVl1yz1fjJN1BCVIRSx3ZiLsj01dh+xchyM=";
})
];
postPatch =