Posted By: Matthias Tarasiewicz
Date: 2007-10-17 01:32
Summary: Instiki 0.12 important security update
Project: Instiki

0.12 is mainly a bugfix release. We recommend all instiki Users to upgrade.
In this version, some security holes where fixed
- An XSS vulnerability in categories
- An XSS vulnerability in <nowiki>
- fixes that Instiki allows "dangerous" operations as HTTP GETs

as well as some other small improvements.
- fixes for instiki running on mongrel
- fixes for instiki running on mongrel_cluster

We added a lot of tests, synced with Jacques Distler's version and fixed
small bugs as well. A note to Mac OSX users: use the Ruby One-Click-Installer
for OSX ( http://rubyosx.com ) or make sure you are not running into problems
with sqlite (see http://instiki.5uper.net/instiki/show/SQLite+issues+on+OSX)

Latest News
TZInfo v1.0.0 and TZInfo::Data v1.2013.3 Released
    Philip Ross - 2013-06-02 17:12
icalendar 1.4.0 Released
    Ryan Ahearn - 2013-05-21 23:17
BinData 1.5.0 - source moved to github
    Dion Mendel - 2013-05-21 11:10
v13.5.0 Released !!
    id 774 - 2013-05-18 12:28
Runt v0.9.0 Released
    Matthew Lipper - 2013-05-17 00:11

 

Forums | Admin

Discussion Forums: instiki-0.12-important-security-update

Start New Thread Start New Thread

 

By: G. Gibson
great ... could you put in INTO the gem list? [ reply ]  
2008-01-26 02:04
The last version gem install will get is .10.2 ... could you please update the remote repository to include .12 ??