Skip to content

Backport vuln fix to major version 3#256

Closed
Blackbaud-ShaydeNofziger wants to merge 2 commits intojfhbrook:masterfrom
Blackbaud-ShaydeNofziger:bugfix/backport-vuln
Closed

Backport vuln fix to major version 3#256
Blackbaud-ShaydeNofziger wants to merge 2 commits intojfhbrook:masterfrom
Blackbaud-ShaydeNofziger:bugfix/backport-vuln

Conversation

@Blackbaud-ShaydeNofziger
Copy link

@Blackbaud-ShaydeNofziger Blackbaud-ShaydeNofziger commented May 2, 2019

Cherry-picked the patch commit that resolved the Open Redirect vulnerability announced.

@Blackbaud-ShaydeNofziger
Copy link
Author

Obviously can't merge to master - we'd need a different target branch to release this through.

@thornjad
Copy link
Contributor

thornjad commented May 2, 2019

@jfhbrook could make a v3 branch or something like that

@Blackbaud-ShaydeNofziger
Copy link
Author

@jfhbrook when you are able, could you please make a new branch, v3 or similar based off of the b1ad801 3.3.1 release commit?

@chase-moskal
Copy link

chase-moskal commented May 2, 2019

instead of waiting around, i suppose there's no harm in anybody temporarily publishing ecstatic-fix-830@3.0.1-fixed.1 or something like that, straight from this forked pr branch, if distributing the fix rapidly was desirable

@jfhbrook
Copy link
Owner

jfhbrook commented May 2, 2019

I can push this out tomorrow morning.

@jfhbrook
Copy link
Owner

jfhbrook commented May 3, 2019

Rather than trying to pull down this branch I just replayed your steps. The result is published as 3.3.2. Cheers!

@jfhbrook jfhbrook closed this May 3, 2019
@Blackbaud-ShaydeNofziger
Copy link
Author

@jfhbrook Awesome, thanks bud!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants