http://hg.code.sf.net:8000/p/roundup/code/atom-log/tip/share/roundup/templates/devel/html/user.help.html Mercurial Repository: p/roundup/code: share/roundup/templates/devel/html/user.help.html history 2024-07-09T09:07:09-04:00 fix(security): fix CVE-2024-39124, CVE-2024-39124, and CVE-2024-39125 http://hg.code.sf.net:8000/p/roundup/code/#changeset-28aa76443f58bc1605a9933bb4ea4d599c97af5a John Rouillard rouilj@ieee.org 2024-07-09T09:07:09-04:00 2024-07-09T09:07:09-04:00
changeset 28aa76443f58
branch
bookmark
tag
user John Rouillard <rouilj@ieee.org>
description fix(security): fix CVE-2024-39124, CVE-2024-39124, and CVE-2024-39125

Directions for fixing:

* `CVE-2024-39124`_ - :ref:`classhelpers (_generic.help.html) are
vulnerable to an XSS attack. <CVE-2024-39124>` Requires fixing
tracker homes.
* `CVE-2024-39125`_ - :ref:`if Referer header is set to a script
tag, it will be executed. <CVE-2024-39125>` Fixed in release 2.4.0,
directions available for fixing in prior versions.
* `CVE-2024-39126`_ - :ref:`PDF, XML and SVG files downloaded from
an issue can contain embedded JavaScript which is
executed. <CVE-2024-39126>` Fixed in release 2.4.0, directions
available for fixing in prior versions.

prior to 2.4.0 release this weekend that fixes the last two CVE's.
files
Update the version string. http://hg.code.sf.net:8000/p/roundup/code/#changeset-fb9725793786ea58449012a9e6c8f8b3eb98be60 John Rouillard rouilj@ieee.org 2023-03-04T16:56:42-05:00 2023-03-04T16:56:42-05:00
changeset fb9725793786
branch
bookmark
tag
user John Rouillard <rouilj@ieee.org>
description Update the version string.
files
Upgrade from jquery-3.5.1 to jquery-3.6.3 http://hg.code.sf.net:8000/p/roundup/code/#changeset-9fcb7e3819120bf079441897551db40e0bb8c98e John Rouillard rouilj@ieee.org 2023-03-04T15:01:33-05:00 2023-03-04T15:01:33-05:00
changeset 9fcb7e381912
branch
bookmark
tag
user John Rouillard <rouilj@ieee.org>
description Upgrade from jquery-3.5.1 to jquery-3.6.3

Modified files that used the older version.
files
issue2551100 - out of date jquery fix security and user.help.html http://hg.code.sf.net:8000/p/roundup/code/#changeset-944e4dfcc9b7189b90ccd482d71437b8e1a9660a John Rouillard rouilj@ieee.org 2020-11-27T00:15:26-05:00 2020-11-27T00:15:26-05:00
changeset 944e4dfcc9b7
branch
bookmark
tag
user John Rouillard <rouilj@ieee.org>
description issue2551100 - out of date jquery fix security and user.help.html

GitHub security scan flagged instances of older 1.3.2 jquery. Updated
jQuery to current version 3.5.1 and fix user.help.html to have apply
button work.
files
Improve query UI. http://hg.code.sf.net:8000/p/roundup/code/#changeset-04264349c483175785ac078a07836d653a4158af Stefan Seefeld stefan@seefeld.name 2010-11-02T01:54:17+00:00 2010-11-02T01:54:17+00:00
changeset 04264349c483
branch
bookmark
tag
user Stefan Seefeld <stefan@seefeld.name>
description Improve query UI.
files
Add new tracker template. http://hg.code.sf.net:8000/p/roundup/code/#changeset-b419f29b1e2fdeb2aaf2c45644049517e404a444 Stefan Seefeld stefan@seefeld.name 2010-10-12T01:14:07+00:00 2010-10-12T01:14:07+00:00
changeset b419f29b1e2f
branch
bookmark
tag
user Stefan Seefeld <stefan@seefeld.name>
description Add new tracker template.
files
[gsoc-2009] Small validity fixes. http://hg.code.sf.net:8000/p/roundup/code/#changeset-27db828ed210cf5b3c212527c436941c3af08e7b Stefan Seefeld stefan@seefeld.name 2009-06-17T02:04:14+00:00 2009-06-17T02:04:14+00:00
changeset 27db828ed210
branch gsoc-2009
bookmark
tag
user Stefan Seefeld <stefan@seefeld.name>
description Small validity fixes.
files
[gsoc-2009] Add new tracker template sandbox. http://hg.code.sf.net:8000/p/roundup/code/#changeset-115e9883311e2659e6a8029909628daefa297cce Stefan Seefeld stefan@seefeld.name 2009-06-02T00:41:57+00:00 2009-06-02T00:41:57+00:00
changeset 115e9883311e
branch gsoc-2009
bookmark
tag
user Stefan Seefeld <stefan@seefeld.name>
description Add new tracker template sandbox.
files