Critical vulnerability in 4.0.1

60 views
Skip to first unread message

davidbqzt

unread,
May 26, 2020, 10:06:59 PM5/26/20
to ASTPP
I've just discovered this:


That's very serious, is there a solution yet? when will it be available?

This should be announced to the community and highlighted in forums and maybe through an email.

Thanks.

davidbqzt

unread,
May 27, 2020, 1:05:27 AM5/27/20
to ASTPP
Searching in Jira I see that there is a case opened for vulnerabilities EDB-ID:47900 and EDB-ID:47889, a month ago!, Samir Doshi is assigned to the case, but is still with no solution.

Both are serious critical security bugs, that's unacceptable.

What can we do? how can we help you? all our systems are vulnerable! it's urgent, let us know how to help.

Thanks.

Hemdip Badani

unread,
Jul 2, 2020, 4:12:22 AM7/2/20
to ASTPP
Hello David,

EDB-ID:47900 is fixed and merged in ASTPP, for EDB-ID:47889 we will fix it soon and release patch for same

Luciano Moreira

unread,
Jul 2, 2020, 7:33:38 AM7/2/20
to ASTPP
How to update ASTPP 4.0.1 to latest code in github?

Hemdip Badani

unread,
Jul 6, 2020, 5:52:33 AM7/6/20
to ASTPP
Hello,

Out topic because original concern is related to security issue,

Anyways which version are you currently using @Luciano?

--
=====================================================================
Documentation: https://docs.astppbilling.org/display/itplmars/ASTPP
Please contact at sa...@inextrix.com for commercial support.
---
You received this message because you are subscribed to the Google Groups "ASTPP" group.
To unsubscribe from this group and stop receiving emails from it, send an email to astpp+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/astpp/484a3bbb-8837-4c24-a45d-ff2fd34cb66bn%40googlegroups.com.


--
Hemdip Badani
QA Team Lead
iNextrix Technologies Pvt Ltd.

Disclaimer:
The information contained in this communication is confidential and may be legally privileged. It is intended solely for the use of the individual or entity to whom it is addressed and others authorized to receive it. If you are not the intended recipient you are hereby notified that any disclosure, copying, distribution or taking action in reliance of the contents of this information is strictly prohibited and may be unlawful. Please notify the sender immediately and destroy all copies of this message and any attachments contained in it.
Reply all
Reply to author
Forward
0 new messages