Provide build with security updates (OD-207)
bufferUnderrun opened 5 years ago

Hi Robin,

It seems your last commits fix some security vulnerabilties.

Can you provide a build with theses updates and in a more general way as soon as you fix security issues ?

Our onedev service is exposed outside our organisation so it must be secure as soon as possible.

Thanks

  • bufferUnderrun commented 5 years ago

    Do you have a sort of mailing list or another way to contact you for things that are not really issues but we need to discuss ?

  • Robin Shen commented 5 years ago

    I am fixing all found security vulnerabilities and will release a patch version soon. For discussions, you may just create an issue with discussion type.

  • Robin Shen commented 5 years ago

    For now, please do not expose your onedev service to outside as some security vulnerabilities are quite severe (result in remote code execution and leak code access token)

  • bufferUnderrun commented 5 years ago

    you mean all vulnerabilites have not been fix, some are still in v4.0.1 ?

  • Robin Shen commented 5 years ago

    4.0.1 fixes most severe ones. And 4.0.2 will fix all found vulnerabilities.

  • Robin Shen changed state to 'Closed' 5 years ago
    Previous Value Current Value
    Open
    Closed
  • Robin Shen commented 5 years ago

    All found security vulnerabilities are now fixed in build #1014

  • bufferUnderrun commented 5 years ago

    Thanks !!

issue 1/1
Type
Question
Priority
Normal
Assignee
Issue Votes (0)
Watchers (2)
Reference
OD-207
Please wait...
Connection lost or session expired, reload to recover
Page is in error, reload to recover