Skip to content

Commit

Permalink
Add MyBB 1.8.38
Browse files Browse the repository at this point in the history
  • Loading branch information
dvz committed Apr 30, 2024
1 parent 9c961dd commit adf7615
Show file tree
Hide file tree
Showing 2 changed files with 2,035 additions and 0 deletions.
150 changes: 150 additions & 0 deletions _versions/1.8.38.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,150 @@
---
title: "Version 1.8.38"

version_number: "1.8.38"
version_code: "1838"
release_date: "2024-04-30"

packages:
- type: mybb
formats:
- type: zip
filesize: "2.21 MB"
checksums:
- type: md5
value: a8dfb0ecc8f0ab4341f0648a2018c3f1
- type: sha1
value: 0f71f3e3ef88b900e6a3f10c0ada578ca532a9a5
- type: sha256
value: 302e9584fb8e6212104e7c57a8c00ba8e10c4cfcc2604b6de08be483d6029729
- type: sha512
value: ad142d8433569354c5dd369cf4888700a92e700ee2bf7076ecda2c4f8c9e23775304815dec115fa10b14684723c3952674c980db49383fecced79a8b5ea5cb3f
locations:
- name: resources.mybb.com/downloads/

- type: changed_files
formats:
- type: zip
filesize: "0.6 MB"
checksums:
- type: md5
value: a84d3abe4954a433c2631f427aaaf593
- type: sha1
value: 20989c5fc4b2bc4eb4c8082594cb5f1e44d1c7f0
- type: sha256
value: 1ada6ade5fc14c1d9e476ed18b7b7ba8ef4356f86ffbb3760c803807d8346472
- type: sha512
value: a0ce6ac13ce99fd7b482330c847bea1aeee448d8f2f21d5a19239df1f23a642ff68e515c457adf6379f5e7dc063ea44e27ce363afef2ddaaa6bb8fa17d0c6e4a
locations:
- name: resources.mybb.com/downloads/

upgrade_script_required: true
resolved_issues_number: "16"
resolved_issues_link: "https://github.com/mybb/mybb/issues?q=is%3Aissue+is%3Aclosed+label%3As%3Aresolved+-label%3Adev-branch+milestone%3A1.8.38"

comment: |
Administrators of installed boards should update the existing configuration (`inc/config.php`) to include all [addresses blocked by default](https://github.com/mybb/mybb/security/advisories/GHSA-qfrj-65mv-h75h) in _Disallowed Remote Addresses_.
resolved_security_issues:
- description: "Incomplete disallowed remote addresses list SSRF"
severity: "low"
cve_id: "CVE-2024-23336"
cwe_id: "CWE-184"
cwe_name: "Incomplete List of Disallowed Inputs"
cvss_score: "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"
reported_by:
- name: "shin24"
references:
- url: https://github.com/mybb/mybb/security/advisories/GHSA-qfrj-65mv-h75h
title: "Advisory: Incomplete disallowed remote addresses list SSRF"
type: advisory
- description: "Backups directory .htaccess deletion"
severity: "low"
cve_id: "CVE-2024-23335"
cwe_id: "CWE-20"
cwe_name: "Improper Input Validation"
cvss_score: "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
reported_by:
- name: "shin24"
references:
- url: https://github.com/mybb/mybb/security/advisories/GHSA-94xr-g4ww-j47r
title: "Advisory: Backups directory .htaccess deletion"
type: advisory

changed_language_files_number: "4"

changed_files:
- admin:
- modules:
- config:
- settings.php
- forum:
- attachments.php
- management.php
- home:
- preferences.php
- tools:
- adminlog.php
- backupdb.php
- user:
- users.php
- index.php
- inc:
- 3rdparty:
- 2fa:
- GoogleAuthenticator.php
- diff:
- Diff:
- Engine:
- Native.php
- datahandlers:
- pm.php
- post.php
- languages:
- english:
- admin:
- global.lang.php
- forumdisplay.lang.php
- moderation.lang.php
- showthread.lang.php
- english.php
- mailhandlers:
- php.php
- class_core.php
- class_error.php
- class_moderation.php
- class_session.php
- class_templates.php
- functions.php
- functions_online.php
- install:
- resources:
- language.lang.php
- mybb_theme.xml
- upgrade59.php
- index.php
- upgrade.php
- jscripts:
- inline_moderation.js
- thread.js
- forumdisplay.php
- index.php
- member.php
- moderation.php
- newreply.php
- newthread.php
- online.php
- search.php
- showthread.php

changed_templates:
- forumdisplay_inlinemoderation
- forumdisplay_threadlist
- search_results_posts_inlinemoderation
- search_results_threads_inlinemoderation
- showthread
- showthread_inlinemoderation
- showthread_moderationoptions
- showthread_moderationoptions_threadnotes

---
Loading

0 comments on commit adf7615

Please sign in to comment.