ChiliProject 3.7.0 has just been released. This release is a security release to fix security issues in Rails (CVE-2013-0277), the JSON gem (CVE-2013-0333, CVE-2013-0269) and with MySQL’s handling of strings and numbers during value comparison. This release contains no new features and 1 other bug fix for last tag in the Liquid template language. It is suitable for use [...]
About Holger Just
Half-time Ruby and Rails developer and half-time friendly operations guy, I try to improve the world one step at a time, striving for perfection along the way. You can follow me on Twitter or subscribe to my blog.Author Archive | Holger Just
ChiliProject 2.10.0 released: Important Security Update!
ChiliProject 2.10.0 has just been released. This release is a security release to fix security issues in Rails (CVE-2013-0277), the JSON gem (CVE-2013-0333, CVE-2013-0269) and with MySQL’s handling of strings and numbers during value comparison. This release contains no other bug fixes or new features and is released for users who are unable to upgrade to ChiliProject 3.7.0. It is [...]
ChiliProject 3.5.1 released: Security Release
ChiliProject 3.5.1 has just been released. This release is a security release to fix a security issue of Rails (CVE-2013-0155) which allows attackers to issue unexpected database queries with IS NULL or empty where clauses. The vulnerability does not allow attackers to insert arbitrary values into an SQL query. Additional details are available in the updated advisory of [...]
ChiliProject 2.8.1 released: Security Release
ChiliProject 2.8.1 has just been released. This release is a security release to fix a security issue of Rails (CVE-2013-0155) which allows attackers to issue unexpected database queries with IS NULL or empty where clauses. The vulnerability does not allow attackers to insert arbitrary values into an SQL query. Additional details are available in the updated advisory of [...]
ChiliProject 3.5.0 released: Important Security Update!
ChiliProject 3.5.0 has just been released. This release is a security release to fix a severe security issue of Rails (CVE-2013-0156) which allows attackers to inject and execute arbitrary code on the server hosting ChiliProject. This bug was fixed in Rails 2.3.15, which is included in this release of ChiliProject. This release contains no other bug fixes or [...]
ChiliProject 3.2.2 released
ChiliProject 3.2.2 has just been released. This release is a security release to fix two security issues of Rails (CVE-2012-2694 and CVE-2012-2695) which allowe attackers to inject certain forms of SQL into the database queries generated by ChiliProject. The bugs were fixed in Rails 3.2.6. We have backported them to the version of Rails we [...]
ChiliProject 2.7.3 released
ChiliProject 2.7.3 has just been released. This release is a security release to fix two security issues of Rails (CVE-2012-2694 and CVE-2012-2695) which allowe attackers to inject certain forms of SQL into the database queries generated by ChiliProject. The bugs were fixed in Rails 3.2.6. We have backported them to the version of Rails we [...]
ChiliProject 3.2.0 released
ChiliProject 3.2.0 has just been released. It includes some new features and bugfixes for ChiliProject 3.1.0 as well as a security fix of Rails which was backported to our version. It is suitable for use on production websites and we recommend that all users download the release as soon as possible. Users of the old [...]
ChiliProject 2.7.2 released
ChiliProject 2.7.2 has just been released. This release is a security release to fix a security issue of Rails (CVE-2012-2660). It addresses a bug in the parsing of requests by ActionPack. It was fixed in Rails 3.2.4 and was backported to the Rails version used by us. This release contains no other bug fixes or [...]
ChiliProject 2.7.1 released
ChiliProject 2.7.1 has just been released. This release is a security release to fix several mass-assignment vulnerabilities. It contains no other bug fixes or new features and is released for users who are unable to upgrade to ChiliProject 3.1.0. It is suitable for use on production websites running ChiliProject 2.x and we highly recommend that [...]
- Introducing ChiliProject – A community fork of Redmine 2011/02/02
- ChiliProject 2.0.0 Released 2011/07/01
- Retrospective 2013/01/02
- ChiliProject 3.0.0 released 2012/02/06
- New Design For ChiliProject 2011/12/16
- ChiliProject 3.8.0 released: Security Update 2013/03/19
- ChiliProject 2.11.0 released: Security Update 2013/03/19
- ChiliProject 3.7.0 released: Important security update! 2013/02/13
- ChiliProject 2.10.0 released: Important Security Update! 2013/02/13
- ChiliProject 3.6.0 released: Important Security Update! 2013/01/29
Archives
- March 2013 (2)
- February 2013 (2)
- January 2013 (11)
- July 2012 (2)
- June 2012 (5)
- May 2012 (1)
- April 2012 (2)
- February 2012 (2)
- January 2012 (2)
- December 2011 (2)
- November 2011 (2)
- October 2011 (4)
- August 2011 (3)
- July 2011 (3)
- June 2011 (4)
- May 2011 (5)
- March 2011 (2)
- February 2011 (3)
Twitter