Outage - blogs.fedoraproject.org #2527

Closed
opened 2010-12-22 07:28:58 +00:00 by ricky · 2 comments

= phenomenon =
blogs.fedoraproject.org has currently been preemptively taken down due to known security issues in our current version of wordpress.

= recommendation =
Update wordpress-mu or find a hotfix for this and any other known issues.

= phenomenon = blogs.fedoraproject.org has currently been preemptively taken down due to known security issues in our current version of wordpress. = recommendation = Update wordpress-mu or find a hotfix for this and any other known issues.
Author

The bug in question is http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=605603 (blog authors can perform SQL injection).

I've filed bugzilla bugs https://bugzilla.redhat.com/show_bug.cgi?id=664873 and https://bugzilla.redhat.com/show_bug.cgi?id=664886 to the wordpress-mu and wordpress packages.

The bug in question is http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=605603 (blog authors can perform SQL injection). I've filed bugzilla bugs https://bugzilla.redhat.com/show_bug.cgi?id=664873 and https://bugzilla.redhat.com/show_bug.cgi?id=664886 to the wordpress-mu and wordpress packages.
Author

This outage is now over, the db logs confirm that apart from our testing, the vulnerabilities were never exploited on our instance.

This outage is now over, the db logs confirm that apart from our testing, the vulnerabilities were never exploited on our instance.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
infra/tickets#2527
No description provided.