-
resoli
Hello Gajim folks.
-
resoli
I administer a gitlab instanc at work, and I have just upgraded to `v16.8.1` because of https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/
-
resoli
I note that https://dev.gajim.org i still on `v16.7.2`which is vulnerable
-
resoli
Today I tried to access https://salsa.debian.org and it doen't seem in good shape ...
-
resoli
Ok, seems debian already repaired 💪️✎ -
resoli
Ok, seems debian already repaired salsa ... 💪️ ✏
-
resoli
Maybe they were simply upgrading this morning, now they are on `v16.5.8` ( *not* vulnerable )
-
cal0pteryx
asterix ^
-
lovetox
resoli, v16.7.2 is from Jan 11, 2024
-
lovetox
we update regulary, but not weekly :D
-
cal0pteryx
Bus this one has a CVE of 9.9 :D
-
resoli
lovetox: Same for me, I updated last week or so, but as cal0pteryx suggests, this is a special case.
-
resoli
https://www.bleepingcomputer.com/news/security/over-5-300-gitlab-servers-exposed-to-zero-click-account-takeover-attacks/
-
resoli
And this is reporting about former vulnerability, not latest one ...✎ -
resoli
This is reporting about former vulnerability, ~not~ *and* latest one ... ✏
-
resoli
And this is reporting about former vulnerability, not latest one ... ✏
-
resoli
https://nvd.nist.gov/vuln/detail/CVE-2024-0402