Is WinterCMS patched for OC Security advisor CVE-2021-32648? #406
-
I've just received an October security advisory for CVE-2021-32648. Is WinterCMS affected by this vulnerability? |
Beta Was this translation helpful? Give feedback.
Answered by
LukeTowers
Jan 18, 2022
Replies: 1 comment 1 reply
-
Yes, we've been patched since v1.1.3 in April last year. We'll be releasing security advisories of our own shortly. While the October team has proven unwilling to share security issues that could be harmful to our users as well as theirs; we do monitor their 1.0 and 1.1 branches for any changes that could indicate a risk for our users as well. |
Beta Was this translation helpful? Give feedback.
1 reply
Answer selected by
LukeTowers
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Yes, we've been patched since v1.1.3 in April last year. We'll be releasing security advisories of our own shortly.
While the October team has proven unwilling to share security issues that could be harmful to our users as well as theirs; we do monitor their 1.0 and 1.1 branches for any changes that could indicate a risk for our users as well.