Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Fediverse
  3. NodeBB 2.8.17 & 3.3.5 Security Releases

NodeBB 2.8.17 & 3.3.5 Security Releases

Scheduled Pinned Locked Moved Fediverse
security2.8.173.3.5
16 Posts 4 Posters 117 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • baris@community.nodebb.orgB [email protected]

    Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

    As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

    The fix is included in the latest 2.8.17 & 3.3.5 releases
    https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
    https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

    frankm@community.nodebb.orgF This user is from outside of this forum
    frankm@community.nodebb.orgF This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #7

    @baris Works. Thank you!

    1 Reply Last reply
    0
    • baris@community.nodebb.orgB [email protected]

      Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

      As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

      The fix is included in the latest 2.8.17 & 3.3.5 releases
      https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
      https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

      frankm@community.nodebb.orgF This user is from outside of this forum
      frankm@community.nodebb.orgF This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #8
      ~/nodebb$ git fetch
      remote: Enumerating objects: 9, done.
      remote: Counting objects: 100% (9/9), done.
      remote: Compressing objects: 100% (3/3), done.
      remote: Total 9 (delta 6), reused 9 (delta 6), pack-reused 0
      Unpacking objects: 100% (9/9), 904 bytes | 75.00 KiB/s, done.
      From https://github.com/NodeBB/NodeBB
         05a7c7610d..d36140eb5f  develop    -> origin/develop
         fb43f9ae10..dc14d6a8d1  v2.x       -> origin/v2.x
      ~/nodebb$ git reset --hard origin/v3.x
      HEAD is now at a67f84ea5b chore: incrementing version number - v3.3.4
      

      Ok, i think you are working.

      1 Reply Last reply
      0
      • baris@community.nodebb.orgB [email protected]

        Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

        As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

        The fix is included in the latest 2.8.17 & 3.3.5 releases
        https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
        https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

        S This user is from outside of this forum
        S This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #9

        after updating, my install still says its running v3.3.4

        1 Reply Last reply
        0
        • baris@community.nodebb.orgB [email protected]

          Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

          As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

          The fix is included in the latest 2.8.17 & 3.3.5 releases
          https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
          https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

          baris@community.nodebb.orgB This user is from outside of this forum
          baris@community.nodebb.orgB This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #10

          @sweetp I might have forgot to increment the version number in package.json for 3.3.5, I did that later https://github.com/NodeBB/NodeBB/commit/055762e69e66d8a4fb30755a7b84bf52613c9e57.

          1 Reply Last reply
          0
          • baris@community.nodebb.orgB [email protected]

            Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

            As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

            The fix is included in the latest 2.8.17 & 3.3.5 releases
            https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
            https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

            frankm@community.nodebb.orgF This user is from outside of this forum
            frankm@community.nodebb.orgF This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #11

            On another forum, i got nothing when i do

            git fetch
            

            ❓

            1 Reply Last reply
            0
            • baris@community.nodebb.orgB [email protected]

              Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

              As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

              The fix is included in the latest 2.8.17 & 3.3.5 releases
              https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
              https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

              frankm@community.nodebb.orgF This user is from outside of this forum
              frankm@community.nodebb.orgF This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #12
              ~/nodebb$ git reset --hard v3.3.5
              fatal: ambiguous argument 'v3.3.5': unknown revision or path not in the working tree.
              Use '--' to separate paths from revisions, like this:
              'git  [...] -- [...]'
              
              julian@community.nodebb.orgJ 1 Reply Last reply
              0
              • frankm@community.nodebb.orgF [email protected]
                ~/nodebb$ git reset --hard v3.3.5
                fatal: ambiguous argument 'v3.3.5': unknown revision or path not in the working tree.
                Use '--' to separate paths from revisions, like this:
                'git  [...] -- [...]'
                
                julian@community.nodebb.orgJ This user is from outside of this forum
                julian@community.nodebb.orgJ This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #13

                @FrankM You'll need to either git pull or git fetch first.

                1 Reply Last reply
                0
                • baris@community.nodebb.orgB [email protected]

                  Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                  As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                  The fix is included in the latest 2.8.17 & 3.3.5 releases
                  https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                  https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                  frankm@community.nodebb.orgF This user is from outside of this forum
                  frankm@community.nodebb.orgF This user is from outside of this forum
                  [email protected]
                  wrote on last edited by
                  #14

                  Ok, git pull works

                  ~/nodebb$ git pull
                  remote: Enumerating objects: 475, done.
                  remote: Counting objects: 100% (475/475), done.
                  remote: Compressing objects: 100% (231/231), done.
                  remote: Total 475 (delta 248), reused 469 (delta 244), pack-reused 0
                  Receiving objects: 100% (475/475), 417.93 KiB | 13.06 MiB/s, done.
                  Resolving deltas: 100% (248/248), completed with 54 local objects.
                  From https://github.com/NodeBB/NodeBB
                     7d9ff9bf4e..d36140eb5f  develop    -> origin/develop
                     c44ddb10e7..055762e69e  master     -> origin/master
                     638e098f30..dc14d6a8d1  v2.x       -> origin/v2.x
                   * [new tag]               v2.8.17    -> v2.8.17
                   * [new tag]               v3.3.5     -> v3.3.5
                  

                  My other forum show this

                  ~/nodebb$ git pull
                  hint: You have divergent branches and need to specify how to reconcile them.
                  hint: You can do so by running one of the following commands sometime before
                  hint: your next pull:
                  hint: 
                  hint:   git config pull.rebase false  # merge
                  hint:   git config pull.rebase true   # rebase
                  hint:   git config pull.ff only       # fast-forward only
                  hint: 
                  hint: You can replace "git config" with "git config --global" to set a default
                  hint: preference for all repositories. You can also pass --rebase, --no-rebase,
                  hint: or --ff-only on the command line to override the configured default per
                  hint: invocation.
                  fatal: Need to specify how to reconcile divergent branches.
                  
                  1 Reply Last reply
                  0
                  • baris@community.nodebb.orgB [email protected]

                    Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                    As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                    The fix is included in the latest 2.8.17 & 3.3.5 releases
                    https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                    https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                    julian@community.nodebb.orgJ This user is from outside of this forum
                    julian@community.nodebb.orgJ This user is from outside of this forum
                    [email protected]
                    wrote on last edited by
                    #15

                    Fixing diverged branches is outside of scope of this forum, sorry 😬

                    https://stackoverflow.com/questions/2452226/master-branch-and-origin-master-have-diverged-how-to-undiverge-branches

                    https://poanchen.github.io/blog/2020/09/19/what-to-do-when-git-branch-has-diverged

                    1 Reply Last reply
                    0
                    • baris@community.nodebb.orgB [email protected]

                      Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                      As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                      The fix is included in the latest 2.8.17 & 3.3.5 releases
                      https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                      https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                      frankm@community.nodebb.orgF This user is from outside of this forum
                      frankm@community.nodebb.orgF This user is from outside of this forum
                      [email protected]
                      wrote on last edited by
                      #16

                      I somehow got it to v3.3.5 now. Please do not ask how 😉 I'm thinking about reinstalling to start cleanly.

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups