Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Backport release-24.11] mmctl: 9.11.7 -> 9.11.8 #376596

Merged
merged 1 commit into from
Jan 25, 2025

Conversation

nixpkgs-ci[bot]
Copy link
Contributor

@nixpkgs-ci nixpkgs-ci bot commented Jan 25, 2025

Bot-based backport to release-24.11, triggered by a label in #376561.

  • Before merging, ensure that this backport is acceptable for the release.
    • Even as a non-commiter, if you find that it is not acceptable, leave a comment.

(cherry picked from commit 6d212a9)
@nixpkgs-ci nixpkgs-ci bot added the 1.severity: security Issues which raise a security issue, or PRs that fix one label Jan 25, 2025
@nixpkgs-ci nixpkgs-ci bot mentioned this pull request Jan 25, 2025
@numinit
Copy link
Contributor

numinit commented Jan 25, 2025

This fixes MMSA-2025-00428, MMSA-2025-00429, and MMSA-2025-00430, which are (likely) a critical level path traversal, and all have the same root cause in the Boards plugin.

@numinit numinit self-requested a review January 25, 2025 07:29
@numinit
Copy link
Contributor

numinit commented Jan 25, 2025

nixpkgs-review result

Generated using nixpkgs-review.

Command: nixpkgs-review pr 376596


x86_64-linux

✅ 2 packages built:
  • mattermost
  • mmctl

@wegank wegank added the 12.approvals: 1 This PR was reviewed and approved by one reputable person label Jan 25, 2025
@NickCao NickCao merged commit 136caba into release-24.11 Jan 25, 2025
28 of 30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one 12.approvals: 1 This PR was reviewed and approved by one reputable person
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants