Gajim - 2024-01-26


  1. resoli

    Hello Gajim folks.

  2. resoli

    I administer a gitlab instanc at work, and I have just upgraded to `v16.8.1` because of https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/

  3. resoli

    I note that https://dev.gajim.org i still on `v16.7.2`which is vulnerable

  4. resoli

    Today I tried to access https://salsa.debian.org and it doen't seem in good shape ...

  5. resoli

    Ok, seems debian already repaired 💪️

  6. resoli

    Ok, seems debian already repaired salsa ... 💪️

  7. resoli

    Maybe they were simply upgrading this morning, now they are on `v16.5.8` ( *not* vulnerable )

  8. cal0pteryx

    asterix ^

  9. lovetox

    resoli, v16.7.2 is from Jan 11, 2024

  10. lovetox

    we update regulary, but not weekly :D

  11. cal0pteryx

    Bus this one has a CVE of 9.9 :D

  12. resoli

    lovetox: Same for me, I updated last week or so, but as cal0pteryx suggests, this is a special case.

  13. resoli

    https://www.bleepingcomputer.com/news/security/over-5-300-gitlab-servers-exposed-to-zero-click-account-takeover-attacks/

  14. resoli

    And this is reporting about former vulnerability, not latest one ...

  15. resoli

    This is reporting about former vulnerability, ~not~ *and* latest one ...

  16. resoli

    And this is reporting about former vulnerability, not latest one ...

  17. resoli

    https://nvd.nist.gov/vuln/detail/CVE-2024-0402