-
Notifications
You must be signed in to change notification settings - Fork 197
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
docs(reference): add security notice 15 #5150
base: main
Are you sure you want to change the base?
Conversation
|
||
#### Impact | ||
|
||
The version of Camunda Optimize was affected by a vulnerability that allows a malicious attacker to craft Camunda URLs that could execute Javascript code. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🚫 [vale] reported by reviewdog 🐶
[all.glossary] Inconsistent spelling detected. Use JavaScript
instead of Javascript
. Review the WCoE glossary - https://confluence.camunda.com/x/b5RZBw .
@buccarel can you please include more context for this security notice? Usually these require immediate review/merge/publish, so I'm surprised to see you've aligned it to an alpha/minor. |
docs/reference/notices.md
Outdated
### Notice 14 | ||
|
||
#### Publication date | ||
|
||
March 11th, 2025 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can these both be listed under the same security notice? #5149
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
They are separate things in separate components. I assume we should have different security notices for these?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Generally no issue, but we need to use the right number and the Javascript spelling issue looks legit
docs/reference/notices.md
Outdated
### Notice 14 | ||
|
||
#### Publication date | ||
|
||
March 11th, 2025 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
They are separate things in separate components. I assume we should have different security notices for these?
5336011
to
6a65be3
Compare
@akeller this issue was reported to us right before we did the 8.6.6 release. We could squeeze it in that same release just in time, and we took advantage of the release being already scheduled. With different circumstances, we would have done an emergency, out-of-schedule rollout |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I've made some rewording suggestions, but I'm not clear about exactly what the past/present tense usage should be here as I don't know enough about this issue to tell quickly. Please use this suggestion as guidance. However, I think the rewording around "The version of Camunda" does need to be applied at least, as I'm not sure currently what's there makes sense?
Cautiously approving to unblock if there is urgency, but I suggest @akeller takes a look as well if there is time?
Co-authored-by: Mark Sellings <[email protected]>
Co-authored-by: Mark Sellings <[email protected]>
Co-authored-by: Mark Sellings <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Lgtm - approved from a writing/grammar point of view! 👍 🚀
Description
When should this change go live?
March 11, 2025
bug
orsupport
label)available & undocumented
label)hold
label)low prio
label)PR Checklist
/docs
directory (version 8.8)./versioned_docs/version-8.7/
directory (version 8.7)./versioned_docs
directory.@camunda/tech-writers
unless working with an embedded writer.