Tag Archives | 3.x series

ChiliProject 3.8.0 released: Security Update

ChiliProject 3.8.0 has just been released. This release is a security release to fix security issues in Rails (CVE-2013-1854 among other security advisories not relevant to ChiliProject). This release contains no new features and 3 other bug fixes. It is suitable for use on production websites running ChiliProject 3.x. While the issue can only be exploited for DoS attacks, we [...]

Read full story Comments { 1 }

ChiliProject 3.7.0 released: Important security update!

ChiliProject 3.7.0 has just been released. This release is a security release to fix security issues in Rails (CVE-2013-0277), the JSON gem (CVE-2013-0333, CVE-2013-0269) and with MySQL’s handling of strings and numbers during value comparison. This release contains no new features and 1 other bug fix for last tag in the Liquid template language. It is suitable for use [...]

Read full story Comments { 0 }

ChiliProject 3.6.0 released: Important Security Update!

ChiliProject 3.6.0 has just been released. This release is a security release to fix a severe security issue of Rails (CVE-2013-0333) which allows attackers to inject and execute arbitrary code on the server hosting ChiliProject. This bug was fixed in Rails 2.3.16, which is included in this release of ChiliProject. This release contains 1 other bug fix and no new [...]

Read full story Comments { 1 }

ChiliProject 3.5.1 released: Security Release

ChiliProject 3.5.1 has just been released. This release is a security release to fix a security issue of Rails (CVE-2013-0155) which allows attackers to issue unexpected database queries with IS NULL or empty where clauses. The vulnerability does not allow attackers to insert arbitrary values into an SQL query. Additional details are available in the updated advisory of [...]

Read full story Comments { 0 }

ChiliProject 3.5.0 released: Important Security Update!

ChiliProject 3.5.0 has just been released. This release is a security release to fix a severe security issue of Rails (CVE-2013-0156) which allows attackers to inject and execute arbitrary code on the server hosting ChiliProject. This bug was fixed in Rails 2.3.15, which is included in this release of ChiliProject. This release contains no other bug fixes or [...]

Read full story Comments { 1 }

ChiliProject 3.4.0 released

ChiliProject 3.4.0 has just been released. It includes lots of bug fixes for ChiliProject 3.3.0 as well as 3 security fixes. It is suitable for use on production websites and we highly recommend that all users download the release as soon as possible. Download ChiliProject 3.4.0 What’s included 3.4.0 includes 3 security fixes for Rails [...]

Read full story Comments { 1 }

ChiliProject 3.2.2 released

ChiliProject 3.2.2 has just been released. This release is a security release to fix two security issues of Rails (CVE-2012-2694 and CVE-2012-2695) which allowe attackers to inject certain forms of SQL into the database queries generated by ChiliProject. The bugs were fixed in Rails 3.2.6. We have backported them to the version of Rails we [...]

Read full story Comments { 2 }

ChiliProject 3.2.0 released

ChiliProject 3.2.0 has just been released. It includes some new features and bugfixes for ChiliProject 3.1.0 as well as a security fix of Rails which was backported to our version. It is suitable for use on production websites and we recommend that all users download the release as soon as possible. Users of the old [...]

Read full story Comments { 1 }

ChiliProject 3.1.0 released

ChiliProject 3.1.0 has just been released. It includes some new features and bugfixes for ChiliProject 3.0.0 as well as some critical security fixes. It is suitable for use on production websites and we recommend that all users download the release as soon as possible. Users of the old 2.x release branch, please check the 2.7.1 [...]

Read full story Comments { 1 }
Chili Cupcake

ChiliProject 3.0.0 released

Almost to the day one year after the first announcement of ChiliProject we are proud to announce the final 3.0.0 release of ChiliProject. A birthday party is always very exciting, especially the very first one. We have achieved a lot in this year and we have seen a steady stream of new users and contributors [...]

Read full story Comments { 5 }