Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Fediverse
  3. NodeBB 2.8.17 & 3.3.5 Security Releases

NodeBB 2.8.17 & 3.3.5 Security Releases

Scheduled Pinned Locked Moved Fediverse
security2.8.173.3.5
16 Posts 4 Posters 118 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • baris@community.nodebb.orgB [email protected]

    Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

    As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

    The fix is included in the latest 2.8.17 & 3.3.5 releases
    https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
    https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

    frankm@community.nodebb.orgF This user is from outside of this forum
    frankm@community.nodebb.orgF This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #4
    https:///admin/extend/plugins
    
    1 Reply Last reply
    0
    • baris@community.nodebb.orgB [email protected]

      Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

      As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

      The fix is included in the latest 2.8.17 & 3.3.5 releases
      https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
      https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

      frankm@community.nodebb.orgF This user is from outside of this forum
      frankm@community.nodebb.orgF This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #5
      user_nodebb@webserver2-4gb-nbg1-1:~/nodebb$ ./nodebb upgrade
      
      Updating NodeBB...
      
      1. Updating package.json file with defaults...  OK
      
      2. Bringing base dependencies up to date...  started
      
      changed 2 packages, and audited 920 packages in 3s
      
      94 packages are looking for funding
        run `npm fund` for details
      *delete*
      
      1 Reply Last reply
      0
      • baris@community.nodebb.orgB [email protected]

        Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

        As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

        The fix is included in the latest 2.8.17 & 3.3.5 releases
        https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
        https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

        baris@community.nodebb.orgB This user is from outside of this forum
        baris@community.nodebb.orgB This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #6

        @FrankM the issue with our package manager should be fixed now, can you try again?

        1 Reply Last reply
        0
        • baris@community.nodebb.orgB [email protected]

          Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

          As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

          The fix is included in the latest 2.8.17 & 3.3.5 releases
          https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
          https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

          frankm@community.nodebb.orgF This user is from outside of this forum
          frankm@community.nodebb.orgF This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #7

          @baris Works. Thank you!

          1 Reply Last reply
          0
          • baris@community.nodebb.orgB [email protected]

            Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

            As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

            The fix is included in the latest 2.8.17 & 3.3.5 releases
            https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
            https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

            frankm@community.nodebb.orgF This user is from outside of this forum
            frankm@community.nodebb.orgF This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #8
            ~/nodebb$ git fetch
            remote: Enumerating objects: 9, done.
            remote: Counting objects: 100% (9/9), done.
            remote: Compressing objects: 100% (3/3), done.
            remote: Total 9 (delta 6), reused 9 (delta 6), pack-reused 0
            Unpacking objects: 100% (9/9), 904 bytes | 75.00 KiB/s, done.
            From https://github.com/NodeBB/NodeBB
               05a7c7610d..d36140eb5f  develop    -> origin/develop
               fb43f9ae10..dc14d6a8d1  v2.x       -> origin/v2.x
            ~/nodebb$ git reset --hard origin/v3.x
            HEAD is now at a67f84ea5b chore: incrementing version number - v3.3.4
            

            Ok, i think you are working.

            1 Reply Last reply
            0
            • baris@community.nodebb.orgB [email protected]

              Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

              As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

              The fix is included in the latest 2.8.17 & 3.3.5 releases
              https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
              https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

              S This user is from outside of this forum
              S This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #9

              after updating, my install still says its running v3.3.4

              1 Reply Last reply
              0
              • baris@community.nodebb.orgB [email protected]

                Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                The fix is included in the latest 2.8.17 & 3.3.5 releases
                https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                baris@community.nodebb.orgB This user is from outside of this forum
                baris@community.nodebb.orgB This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #10

                @sweetp I might have forgot to increment the version number in package.json for 3.3.5, I did that later https://github.com/NodeBB/NodeBB/commit/055762e69e66d8a4fb30755a7b84bf52613c9e57.

                1 Reply Last reply
                0
                • baris@community.nodebb.orgB [email protected]

                  Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                  As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                  The fix is included in the latest 2.8.17 & 3.3.5 releases
                  https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                  https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                  frankm@community.nodebb.orgF This user is from outside of this forum
                  frankm@community.nodebb.orgF This user is from outside of this forum
                  [email protected]
                  wrote on last edited by
                  #11

                  On another forum, i got nothing when i do

                  git fetch
                  

                  ❓

                  1 Reply Last reply
                  0
                  • baris@community.nodebb.orgB [email protected]

                    Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                    As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                    The fix is included in the latest 2.8.17 & 3.3.5 releases
                    https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                    https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                    frankm@community.nodebb.orgF This user is from outside of this forum
                    frankm@community.nodebb.orgF This user is from outside of this forum
                    [email protected]
                    wrote on last edited by
                    #12
                    ~/nodebb$ git reset --hard v3.3.5
                    fatal: ambiguous argument 'v3.3.5': unknown revision or path not in the working tree.
                    Use '--' to separate paths from revisions, like this:
                    'git  [...] -- [...]'
                    
                    julian@community.nodebb.orgJ 1 Reply Last reply
                    0
                    • frankm@community.nodebb.orgF [email protected]
                      ~/nodebb$ git reset --hard v3.3.5
                      fatal: ambiguous argument 'v3.3.5': unknown revision or path not in the working tree.
                      Use '--' to separate paths from revisions, like this:
                      'git  [...] -- [...]'
                      
                      julian@community.nodebb.orgJ This user is from outside of this forum
                      julian@community.nodebb.orgJ This user is from outside of this forum
                      [email protected]
                      wrote on last edited by
                      #13

                      @FrankM You'll need to either git pull or git fetch first.

                      1 Reply Last reply
                      0
                      • baris@community.nodebb.orgB [email protected]

                        Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                        As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                        The fix is included in the latest 2.8.17 & 3.3.5 releases
                        https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                        https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                        frankm@community.nodebb.orgF This user is from outside of this forum
                        frankm@community.nodebb.orgF This user is from outside of this forum
                        [email protected]
                        wrote on last edited by
                        #14

                        Ok, git pull works

                        ~/nodebb$ git pull
                        remote: Enumerating objects: 475, done.
                        remote: Counting objects: 100% (475/475), done.
                        remote: Compressing objects: 100% (231/231), done.
                        remote: Total 475 (delta 248), reused 469 (delta 244), pack-reused 0
                        Receiving objects: 100% (475/475), 417.93 KiB | 13.06 MiB/s, done.
                        Resolving deltas: 100% (248/248), completed with 54 local objects.
                        From https://github.com/NodeBB/NodeBB
                           7d9ff9bf4e..d36140eb5f  develop    -> origin/develop
                           c44ddb10e7..055762e69e  master     -> origin/master
                           638e098f30..dc14d6a8d1  v2.x       -> origin/v2.x
                         * [new tag]               v2.8.17    -> v2.8.17
                         * [new tag]               v3.3.5     -> v3.3.5
                        

                        My other forum show this

                        ~/nodebb$ git pull
                        hint: You have divergent branches and need to specify how to reconcile them.
                        hint: You can do so by running one of the following commands sometime before
                        hint: your next pull:
                        hint: 
                        hint:   git config pull.rebase false  # merge
                        hint:   git config pull.rebase true   # rebase
                        hint:   git config pull.ff only       # fast-forward only
                        hint: 
                        hint: You can replace "git config" with "git config --global" to set a default
                        hint: preference for all repositories. You can also pass --rebase, --no-rebase,
                        hint: or --ff-only on the command line to override the configured default per
                        hint: invocation.
                        fatal: Need to specify how to reconcile divergent branches.
                        
                        1 Reply Last reply
                        0
                        • baris@community.nodebb.orgB [email protected]

                          Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                          As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                          The fix is included in the latest 2.8.17 & 3.3.5 releases
                          https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                          https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                          julian@community.nodebb.orgJ This user is from outside of this forum
                          julian@community.nodebb.orgJ This user is from outside of this forum
                          [email protected]
                          wrote on last edited by
                          #15

                          Fixing diverged branches is outside of scope of this forum, sorry 😬

                          https://stackoverflow.com/questions/2452226/master-branch-and-origin-master-have-diverged-how-to-undiverge-branches

                          https://poanchen.github.io/blog/2020/09/19/what-to-do-when-git-branch-has-diverged

                          1 Reply Last reply
                          0
                          • baris@community.nodebb.orgB [email protected]

                            Today we are releasing patch versions for 3.x and 2.x lines to fix an xss vulnerability.

                            As mentioned before we will be supporting 1.x and 2.x until August 2024 and August 2025 respectively. This vulnerability does not effect the 1.x releases so there is no patch for it.

                            The fix is included in the latest 2.8.17 & 3.3.5 releases
                            https://github.com/NodeBB/NodeBB/releases/tag/v2.8.17
                            https://github.com/NodeBB/NodeBB/releases/tag/v3.3.5

                            frankm@community.nodebb.orgF This user is from outside of this forum
                            frankm@community.nodebb.orgF This user is from outside of this forum
                            [email protected]
                            wrote on last edited by
                            #16

                            I somehow got it to v3.3.5 now. Please do not ask how 😉 I'm thinking about reinstalling to start cleanly.

                            1 Reply Last reply
                            0
                            Reply
                            • Reply as topic
                            Log in to reply
                            • Oldest to Newest
                            • Newest to Oldest
                            • Most Votes


                            • Login

                            • Login or register to search.
                            • First post
                              Last post
                            0
                            • Categories
                            • Recent
                            • Tags
                            • Popular
                            • World
                            • Users
                            • Groups