Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Repair Jira Macros

Intended 20 23 May 2014

uPortal 4.0.13.1 Announcement

Apereo has released uPortal 4.0.13.1, which is uPortal 4.0.13 with security fixes to properly enforce MANAGE and CONFIG permissions.

 

Features and Changes of Note

...

Prior to this release, portlet administration permissions are bugged such that

  1. CVE-2014-3416 anyone who can SUBSCRIBE the portlet-admin portlet can MANAGE any portlet, regardless of intended delegated administration MANAGE and MANAGE-* permission restrictions , and
  2. CVE-2014-3417 anyone who can SUBSCRIBE a given portlet can enter CONFIG mode of that portlet to the extent that the portlet has a CONFIG mode.



Updating from 4.0.0-4.0.5

Info

If you have data you care about in the UP_LOGIN_EVENT_AGGREGATE table please back it up externally or rename the table before executing the following steps. db-update will drop this table.

After configuring your uPortal 4.0.13.1 source run:

Code Block
ant db-update

 

Where to get it

Downloads: TODO: have a download link http://downloads.jasig.org/uportal/uportal-4.0.13.1/
Release Notes: https://wiki.jasig.org/display/UPC/4.0.13.1
Maven Project Site: http://developer.jasig.org/projects/uportal/4.0.13.1/  

In Maven Central: http://search.maven.org/#browse%7C84002748

 

Full Release Notes

JIRA-generated Release Notes - uPortal - Version 4.0.13.1

TODO: full release notes

-Release Engineer (TODO: credit release engineer)

Security Bug

  • [UP-4105] - CVE-2014-3416 MANAGE[-*] permissions not enforced
  • [UP-4106] - CVE-2014-3417 Any user can Configure any portlet they can SUBSCRIBE

Bug

  • [UP-3869] - Bamboo build failures with 'connection exception: connection failure: java.io.EOFException' on hsql shutdown

 

- Andrew Petro (with a lot of help from Tim Levett )

 

Screenshots

Gallery
titleScreenshots from uPortal 4.0.13.1

Issues addressed in uPortal 4.0.13.1

Jira Legacy
serverJASIG Issue TrackerSystem JIRA
columnskey,summary,type,priority,status,resolution
maximumIssues20
jqlQueryproject = UP AND fixVersion = 4.0.13.1 AND status in (resolved, closed) ORDER BY priority
serverId76221f40d8d429a7-4501dc92-3df13696-857885f0-6c87908cbdf71de5d4e9bcf6

Bugs known to afflict uPortal 4.0.13.1

(Note that this listing is only as good as JIRA issue metadata about affects-version.)

Jira Legacy
serverJASIG Issue TrackerSystem JIRA
columnskey,summary,type,updated,priority,status,resolution
maximumIssues20
jqlQueryproject = UP AND issuetype = Bug AND affectedVersion = 4.0.13.1 ORDER BY priority DESC
serverId76221f40d8d429a7-4501dc92-3df13696-857885f0-6c87908cbdf71de5d4e9bcf6