[Info]Security fix for ihatemoney - please upgrade.

Hi folks, A security release have been issued : 4.1.5 <https://github.com/spiral-project/ihatemoney/releases/tag/4.1.5> This release fixes a serious security issue (CVE-2020-15120) <https://github.com/spiral-project/ihatemoney/security/advisories/GHSA-67j9-c52g-w2q9>. All users are encouraged to upgrade. Fixed * Fix unauthorized access and modification of project data (CVE-2020-15120) (#663 <https://github.com/spiral-project/ihatemoney/pull/663>) Changed * Change mobile icon link (#598 <https://github.com/spiral-project/ihatemoney/pull/598>) * Improve French translation of email templates (#593 <https://github.com/spiral-project/ihatemoney/pull/593>) Added * Add translations for Portuguese (Brazil), Tamil, Hindi Thank you for using ihatemoney :-) Alex

To complete, about 3rd-party packages of IHateMoney: - The YunoHost app has been upgraded (upgrade your apps !) - NixOS 20.3 package has been upgraded (upgrade your distro !) The version including the fix is 4.1.5. Regards, Jocelyn Le mar. 28 juil. 2020 à 20:52, Alexis Métaireau <alexis@notmyidea.org> a écrit :
Hi folks,
A security release have been issued : 4.1.5 <https://github.com/spiral-project/ihatemoney/releases/tag/4.1.5>
This release fixes a serious security issue (CVE-2020-15120) <https://github.com/spiral-project/ihatemoney/security/advisories/GHSA-67j9-c52g-w2q9>.
All users are encouraged to upgrade.
Fixed
* Fix unauthorized access and modification of project data (CVE-2020-15120) (#663 <https://github.com/spiral-project/ihatemoney/pull/663>)
Changed
* Change mobile icon link (#598 <https://github.com/spiral-project/ihatemoney/pull/598>) * Improve French translation of email templates (#593 <https://github.com/spiral-project/ihatemoney/pull/593>)
Added
* Add translations for Portuguese (Brazil), Tamil, Hindi
Thank you for using ihatemoney :-)
Alex _______________________________________________ Info mailing list -- info@ihatemoney.org To unsubscribe send an email to info-leave@ihatemoney.org
participants (2)
-
Alexis Métaireau
-
Jocelyn Delalande