Skip to content

Don't expose ViMbAdmin's patch level in the footer#299

Merged
barryo merged 3 commits intoopensolutions:masterfrom
PhrozenByte:enhancement/DontExposePatchlevel
Feb 23, 2023
Merged

Don't expose ViMbAdmin's patch level in the footer#299
barryo merged 3 commits intoopensolutions:masterfrom
PhrozenByte:enhancement/DontExposePatchlevel

Conversation

@PhrozenByte
Copy link
Copy Markdown
Contributor

Exposing the exact patch level allows attackers to easily identify likely vulnerable instances of ViMbAdmin if a security flaw happens to be found. This commit simply replaces the exact version string ('3.3.0') with the milestone version string ('3.3') in ViMbAdmin's footer. See 013cfec

Additional changes:

Exposing the exact patch level allows attackers to easily identify likely vulnerable instances of ViMbAdmin if a security flaw happens to be found. This commit simply replaces the exact version string ('3.3.0') with the milestone version string ('3.3') in ViMbAdmin's footer.
If Google Groups or any other kind of forum is revived, one should probably rather add the links to ViMbAdmin's website and the GitHub repo instead, not include it in the footer of every single ViMbAdmin instance.
@barryo barryo merged commit 0a2bc5e into opensolutions:master Feb 23, 2023
@barryo
Copy link
Copy Markdown
Member

barryo commented Feb 23, 2023

Merged with minor change - keeping full version for admins.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants