From 4341067c94e593d68c52a243c4d55532f837ebc0 Mon Sep 17 00:00:00 2001 From: Moritz 'e1mo' Fromm Date: Tue, 16 May 2023 08:35:15 +0200 Subject: dokuwiki: 2023-04-04 -> 2023-04-04a Hotfix for a discovered vulnerability (deemed as high[^1]) in the RSS parser allowing cross-site scripting via injected, arbitrary, JavaScript. Changes: https://github.com/dokuwiki/dokuwiki/compare/release-2023-04-04...release-2023-04-04a [^1]: https://huntr.dev/bounties/c6119106-1a5c-464c-94dd-ee7c5d0bece0/ --- pkgs/servers/web-apps/dokuwiki/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/web-apps/dokuwiki/default.nix b/pkgs/servers/web-apps/dokuwiki/default.nix index 888ca6ca239..a95a6acdfb7 100644 --- a/pkgs/servers/web-apps/dokuwiki/default.nix +++ b/pkgs/servers/web-apps/dokuwiki/default.nix @@ -8,13 +8,13 @@ stdenv.mkDerivation rec { pname = "dokuwiki"; - version = "2023-04-04"; + version = "2023-04-04a"; src = fetchFromGitHub { owner = "dokuwiki"; repo = pname; rev = "release-${version}"; - sha256 = "sha256-QJnXKsEhvEcE88wvfMZR2j7X/pW8+28zlEnxhvhl+44="; + sha256 = "sha256-PVfJfGYa2Drf4ljnnhb7kNpjfQlW4dDt5Xd5h+C8tP4="; }; preload = writeText "preload.php" '' -- cgit 1.4.1