Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Info

If you would like to report an issue you believe is security related, please open a new JIRA Issue. Be sure to set the following attributes:

  • Project: COmanage (CO)
  • Issue Type: Bug
  • Security Level: Vulnerability
  • Component: Registry

Alternately, you may notify comanage@sphericalcowgroup.com. Do not email the users or developers lists report issues via the mailing lists or Slack channels, as those are considered public.

In general, you should always upgrade to the latest version of COmanage as soon as practical, upgrading a QA or test server first. The further behind you fall, the harder it will probably be to upgrade if a highly critical security advisory is released.

Security Advisories

AdvisoryAffected ReleasesSeverityExposure
2015-12-090.9.4 and earlierUnknownUnknown
2017-01-300.9.1 through 1.0.5High or Very HighLow
2018-05-300.9.4 through 3.1.0Very HighLow or Medium
2020-05-293.2.4 and earlierUnknownLow
2020-10-29 *3.2.0 through 3.3.0MediumLow
2021-05-24a3.3.0 through 3.3.2MediumLow
2021-05-24b *0.5 through 3.3.2Very HighVaries
2021-12-073.3.0 through 4.0.0MediumLow
2022-02-243.3.0 through 4.0.1MediumLow
2023-10-03a0.8 through 4.2.1MediumLow or Medium
2023-10-03b3.1.0 through 4.2.1Very HighLow

* Advisories that describe unexpected behavior from a supported configuration, not a code exploit

...