Skip to content

No release notes / mentions of vulnerabilities #1445

@eternalflamez

Description

@eternalflamez

Our cockpit instances were breached due to not running 0.11.2 yet.

There is no mention of any vulnerability or fix thereof except for in the commit messages (that only mention it being a "possible" vulnerability, implying it could also be safe). Is it possible to do some automatic release notes based on the git commit names that are part of the releases? Or at least put mentions of these breaches in the main readme.

For those interested, breach information: https://portswigger.net/daily-swig/cockpit-cms-flaws-exposed-web-servers-to-nosql-injection-exploits

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions