Skip to content

Commit

Permalink
[dist] 2.4.7 release notes
Browse files Browse the repository at this point in the history
  • Loading branch information
adrianschroeter committed Mar 12, 2015
1 parent 5559960 commit 7824025
Showing 1 changed file with 30 additions and 0 deletions.
30 changes: 30 additions & 0 deletions ReleaseNotes-2.4.7
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
#
# openSUSE Build Service 2.4.7
#

Updaters from any OBS 2.4 release can just ugrade the packages
and restart all services. Updaters from former releases should
read the README.UPDATERS file.

This release fixes a serious security leak tracked as CVE-2014-0594:
The CSRF protection got incorrectly disabled, this means any
web site can inject actions as long a user has a running session.

All OBS 2.4 admins are requested to updated immediatly to close this
hole.

Feature backports:
==================

* None

Changes:
========

* None

Bugfixes:
=========

* backend: fix arbitrary command execution in service daemon (CVE-2015-0778)

0 comments on commit 7824025

Please sign in to comment.