We’ve released Chef Client 12.21.12, fixing ruby and rubygems security issues:
This release of Chef Client contains Ruby 2.3.5, fixing 4 CVEs:
- CVE-2017-0898
- CVE-2017-10784
- CVE-2017-14033
- CVE-2017-14064
It also contains a new version of Rubygems, fixing 4 CVEs:
- CVE-2017-0899
- CVE-2017-0900
- CVE-2017-0901
- CVE-2017-0902
Please note that due to issues beyond our control, this release is only built for Linux on x86, x86_64 and s390x, FreeBSD, and Windows. We’ll be releasing a new build with support for our other platforms (AIX, Solaris, macOS) as soon as we’re able to.
Regards,
-Thom