[ANNOUNCEMENT] diaspora* security release 0.5.3.1

15 views
Skip to first unread message

Jonne Haß

unread,
Sep 13, 2015, 6:47:19 AM9/13/15
to diaspora...@googlegroups.com, diaspo...@googlegroups.com
We just released diaspora* version 0.5.3.1 which fixes a leakage of
private data to unauthorized users.

diaspora* versions prior 0.5.3.1 leaked potentially private profile data
(namely the bio, birthday, gender and location fields) to unauthorized
users who were sharing with the person and were on a pod that received
the private profile data.

Thanks to @svbergerem for triaging and fixing the issue. We recommend
all podmins to update as soon as possible.

We're sorry for any inconveniences caused.

- The diaspora* development team

signature.asc
Reply all
Reply to author
Forward
0 new messages