Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[24.05] olm: mark as vulnerable #335189

Merged
merged 4 commits into from
Sep 2, 2024
Merged

Commits on Aug 16, 2024

  1. Configuration menu
    Copy the full SHA
    6f63fbf View commit details
    Browse the repository at this point in the history
  2. {cinny,fluffychat,jitsi-meet}: inherit vulnerabilities from olm

    These vendor the libolm code.
    
    (cherry picked from commit bbfd5d1)
    emilazy committed Aug 16, 2024
    Configuration menu
    Copy the full SHA
    56e4b26 View commit details
    Browse the repository at this point in the history

Commits on Aug 25, 2024

  1. olm: add more information to knownVulnerabilities

    CVE numbers were assigned, and This Week in Matrix included an
    announcement from the Matrix.org project lead. An official post from
    the Matrix.org Foundation is apparently still pending.
    
    (cherry picked from commit 069f7de)
    emilazy committed Aug 25, 2024
    Configuration menu
    Copy the full SHA
    c59e18b View commit details
    Browse the repository at this point in the history

Commits on Aug 30, 2024

  1. olm: update vulnerability description

    Additional information has been published by upstream about why they
    believe the vulnerability to not be exploitable over the network:
    https://matrix.org/blog/2024/08/libolm-deprecation/
    
    This commit
    
    * updates the text of the vulnerability warning to indicate that
      upstream does not believe the issues to be exploitable over the
      network, and
    * adds a link to the blog post.
    
    Co-authored-by: Emily <[email protected]>
    Signed-off-by: Sumner Evans <[email protected]>
    (cherry picked from commit 537d3c4)
    sumnerevans authored and emilazy committed Aug 30, 2024
    Configuration menu
    Copy the full SHA
    11e7332 View commit details
    Browse the repository at this point in the history