Closed (fixed)
Project:
Hostmaster (Aegir)
Version:
6.x-2.x-dev
Component:
Code
Priority:
Critical
Category:
Bug report
Assigned:
Reporter:
Created:
7 Jan 2013 at 07:15 UTC
Updated:
7 Jan 2013 at 12:51 UTC
I'm informed by Omega8cc that the security fixes from SA-CONTRIB-2012-080 have not been applied to 6.x-2.x.
Comments
Comment #1
steven jones commentedhttp://drupalcode.org/project/hostmaster.git/patch/8a6110143056406813819... looks to have been applied correctly already.
Comment #2
steven jones commentedhttp://drupalcode.org/project/hostmaster.git/commit/9476561780dfd1bca39c... has been applied too, so actually both the patches in this security release were already included in 6.x-2.x.
Comment #3
omega8cc commentedJust for the record: the patch related to #1585678: SA-CONTRIB-2012-080 - Hostmaster (Aegir) - Access Bypass and Cross Site Scripting (XSS) from May 16, 2012 has been included by anarcat on November 16, 2012 *after* I reported this on the IRC, so before you have created this issue here.
Comment #4
steven jones commentedYeah that's fine, I just wanted to record and make sure that all the patches got applied.