Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Fediverse
  3. NodeBB 2.8.17 & 3.3.5 Security Releases

NodeBB 2.8.17 & 3.3.5 Security Releases

Scheduled Pinned Locked Moved Fediverse
security2.8.173.3.5
16 Posts 4 Posters 50 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • baris@community.nodebb.orgB This user is from outside of this forum
    baris@community.nodebb.orgB This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #1

    Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

    As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

    The fix is included in the latest 2.8.17 & 3.3.5 releases
    https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
    https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

    frankm@community.nodebb.orgF baris@community.nodebb.orgB S julian@community.nodebb.orgJ 13 Replies Last reply
    0
    • baris@community.nodebb.orgB [email protected]

      Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

      As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

      The fix is included in the latest 2.8.17 & 3.3.5 releases
      https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
      https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

      frankm@community.nodebb.orgF This user is from outside of this forum
      frankm@community.nodebb.orgF This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #2

      Before the upgrade i see this?

      grafik.png

      baris@community.nodebb.orgB 1 Reply Last reply
      0
      • frankm@community.nodebb.orgF [email protected]

        Before the upgrade i see this?

        grafik.png

        baris@community.nodebb.orgB This user is from outside of this forum
        baris@community.nodebb.orgB This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #3

        @FrankM when do you get this page?

        1 Reply Last reply
        0
        • baris@community.nodebb.orgB [email protected]

          Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

          As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

          The fix is included in the latest 2.8.17 & 3.3.5 releases
          https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
          https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

          frankm@community.nodebb.orgF This user is from outside of this forum
          frankm@community.nodebb.orgF This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #4
          https:///admin/extend/plugins
          
          1 Reply Last reply
          0
          • baris@community.nodebb.orgB [email protected]

            Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

            As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

            The fix is included in the latest 2.8.17 & 3.3.5 releases
            https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
            https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

            frankm@community.nodebb.orgF This user is from outside of this forum
            frankm@community.nodebb.orgF This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #5
            user_nodebb@webserver2-4gb-nbg1-1:~/nodebb$ ./nodebb upgrade
            
            Updating NodeBB...
            
            1. Updating package.json file with defaults...  OK
            
            2. Bringing base dependencies up to date...  started
            
            changed 2 packages, and audited 920 packages in 3s
            
            94 packages are looking for funding
              run `npm fund` for details
            *delete*
            
            1 Reply Last reply
            0
            • baris@community.nodebb.orgB [email protected]

              Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

              As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

              The fix is included in the latest 2.8.17 & 3.3.5 releases
              https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
              https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

              baris@community.nodebb.orgB This user is from outside of this forum
              baris@community.nodebb.orgB This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #6

              @FrankM the issue with our package manager should be fixed now, can you try again?

              1 Reply Last reply
              0
              • baris@community.nodebb.orgB [email protected]

                Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                The fix is included in the latest 2.8.17 & 3.3.5 releases
                https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                frankm@community.nodebb.orgF This user is from outside of this forum
                frankm@community.nodebb.orgF This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #7

                @baris Works. Thank you!

                1 Reply Last reply
                0
                • baris@community.nodebb.orgB [email protected]

                  Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                  As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                  The fix is included in the latest 2.8.17 & 3.3.5 releases
                  https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                  https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                  frankm@community.nodebb.orgF This user is from outside of this forum
                  frankm@community.nodebb.orgF This user is from outside of this forum
                  [email protected]
                  wrote on last edited by
                  #8
                  ~/nodebb$ git fetch
                  remote: Enumerating objects: 9, done.
                  remote: Counting objects: 100% (9/9), done.
                  remote: Compressing objects: 100% (3/3), done.
                  remote: Total 9 (delta 6), reused 9 (delta 6), pack-reused 0
                  Unpacking objects: 100% (9/9), 904 bytes | 75.00 KiB/s, done.
                  From https://github.com/NodeBB/NodeBB
                     05a7c7610d..d36140eb5f  develop    -> origin/develop
                     fb43f9ae10..dc14d6a8d1  v2.x       -> origin/v2.x
                  ~/nodebb$ git reset --hard origin/v3.x
                  HEAD is now at a67f84ea5b chore: incrementing version number - v3.3.4
                  

                  Ok, i think you are working.

                  1 Reply Last reply
                  0
                  • baris@community.nodebb.orgB [email protected]

                    Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                    As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                    The fix is included in the latest 2.8.17 & 3.3.5 releases
                    https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                    https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                    S This user is from outside of this forum
                    S This user is from outside of this forum
                    [email protected]
                    wrote on last edited by
                    #9

                    after updating, my install still says its running v3.3.4

                    1 Reply Last reply
                    0
                    • baris@community.nodebb.orgB [email protected]

                      Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                      As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                      The fix is included in the latest 2.8.17 & 3.3.5 releases
                      https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                      https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                      baris@community.nodebb.orgB This user is from outside of this forum
                      baris@community.nodebb.orgB This user is from outside of this forum
                      [email protected]
                      wrote on last edited by
                      #10

                      @sweetp I might have forgot to increment the version number in package.json for 3.3.5, I did that later https://github.com/NodeBB/NodeBB/commit/055762e69e66d8a4fb30755a7b84bf52613c9e57.

                      1 Reply Last reply
                      0
                      • baris@community.nodebb.orgB [email protected]

                        Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                        As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                        The fix is included in the latest 2.8.17 & 3.3.5 releases
                        https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                        https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                        frankm@community.nodebb.orgF This user is from outside of this forum
                        frankm@community.nodebb.orgF This user is from outside of this forum
                        [email protected]
                        wrote on last edited by
                        #11

                        On another forum, i got nothing when i do

                        git fetch
                        

                        ❓

                        1 Reply Last reply
                        0
                        • baris@community.nodebb.orgB [email protected]

                          Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                          As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                          The fix is included in the latest 2.8.17 & 3.3.5 releases
                          https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                          https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                          frankm@community.nodebb.orgF This user is from outside of this forum
                          frankm@community.nodebb.orgF This user is from outside of this forum
                          [email protected]
                          wrote on last edited by
                          #12
                          ~/nodebb$ git reset --hard v3.3.5
                          fatal: ambiguous argument 'v3.3.5': unknown revision or path not in the working tree.
                          Use '--' to separate paths from revisions, like this:
                          'git  [...] -- [...]'
                          
                          julian@community.nodebb.orgJ 1 Reply Last reply
                          0
                          • frankm@community.nodebb.orgF [email protected]
                            ~/nodebb$ git reset --hard v3.3.5
                            fatal: ambiguous argument 'v3.3.5': unknown revision or path not in the working tree.
                            Use '--' to separate paths from revisions, like this:
                            'git  [...] -- [...]'
                            
                            julian@community.nodebb.orgJ This user is from outside of this forum
                            julian@community.nodebb.orgJ This user is from outside of this forum
                            [email protected]
                            wrote on last edited by
                            #13

                            @FrankM You'll need to either git pull or git fetch first.

                            1 Reply Last reply
                            0
                            • baris@community.nodebb.orgB [email protected]

                              Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                              As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                              The fix is included in the latest 2.8.17 & 3.3.5 releases
                              https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                              https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                              frankm@community.nodebb.orgF This user is from outside of this forum
                              frankm@community.nodebb.orgF This user is from outside of this forum
                              [email protected]
                              wrote on last edited by
                              #14

                              Ok, git pull works

                              ~/nodebb$ git pull
                              remote: Enumerating objects: 475, done.
                              remote: Counting objects: 100% (475/475), done.
                              remote: Compressing objects: 100% (231/231), done.
                              remote: Total 475 (delta 248), reused 469 (delta 244), pack-reused 0
                              Receiving objects: 100% (475/475), 417.93 KiB | 13.06 MiB/s, done.
                              Resolving deltas: 100% (248/248), completed with 54 local objects.
                              From https://github.com/NodeBB/NodeBB
                                 7d9ff9bf4e..d36140eb5f  develop    -> origin/develop
                                 c44ddb10e7..055762e69e  master     -> origin/master
                                 638e098f30..dc14d6a8d1  v2.x       -> origin/v2.x
                               * [new tag]               v2.8.17    -> v2.8.17
                               * [new tag]               v3.3.5     -> v3.3.5
                              

                              My other forum show this

                              ~/nodebb$ git pull
                              hint: You have divergent branches and need to specify how to reconcile them.
                              hint: You can do so by running one of the following commands sometime before
                              hint: your next pull:
                              hint: 
                              hint:   git config pull.rebase false  # merge
                              hint:   git config pull.rebase true   # rebase
                              hint:   git config pull.ff only       # fast-forward only
                              hint: 
                              hint: You can replace "git config" with "git config --global" to set a default
                              hint: preference for all repositories. You can also pass --rebase, --no-rebase,
                              hint: or --ff-only on the command line to override the configured default per
                              hint: invocation.
                              fatal: Need to specify how to reconcile divergent branches.
                              
                              1 Reply Last reply
                              0
                              • baris@community.nodebb.orgB [email protected]

                                Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                                As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                                The fix is included in the latest 2.8.17 & 3.3.5 releases
                                https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                                https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                                julian@community.nodebb.orgJ This user is from outside of this forum
                                julian@community.nodebb.orgJ This user is from outside of this forum
                                [email protected]
                                wrote on last edited by
                                #15

                                Fixing diverged branches is outside of scope of this forum, sorry 😬

                                https://stackoverflow.com/questions/2452226/master-branch-and-origin-master-have-diverged-how-to-undiverge-branches

                                https://poanchen.github.io/blog/2020/09/19/what-to-do-when-git-branch-has-diverged

                                1 Reply Last reply
                                0
                                • baris@community.nodebb.orgB [email protected]

                                  Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                                  As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                                  The fix is included in the latest 2.8.17 & 3.3.5 releases
                                  https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                                  https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                                  frankm@community.nodebb.orgF This user is from outside of this forum
                                  frankm@community.nodebb.orgF This user is from outside of this forum
                                  [email protected]
                                  wrote on last edited by
                                  #16

                                  I somehow got it to v3.3.5 now. Please do not ask how 😉 I'm thinking about reinstalling to start cleanly.

                                  1 Reply Last reply
                                  0
                                  Reply
                                  • Reply as topic
                                  Log in to reply
                                  • Oldest to Newest
                                  • Newest to Oldest
                                  • Most Votes


                                  • Login

                                  • Login or register to search.
                                  • First post
                                    Last post
                                  0
                                  • Categories
                                  • Recent
                                  • Tags
                                  • Popular
                                  • World
                                  • Users
                                  • Groups