From 1d202809c29b47a95f53cb556f296f2fe0bd7ce6 Mon Sep 17 00:00:00 2001 From: Rafi59 Date: Tue, 8 Aug 2017 12:43:05 +0200 Subject: [PATCH 01/10] Update upgrade.last.sh --- scripts/upgrade.d/upgrade.last.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/scripts/upgrade.d/upgrade.last.sh b/scripts/upgrade.d/upgrade.last.sh index d8874f5..aa30721 100755 --- a/scripts/upgrade.d/upgrade.last.sh +++ b/scripts/upgrade.d/upgrade.last.sh @@ -1,10 +1,10 @@ #!/bin/bash # Version cible de la mise à jour de Nextcloud -VERSION=12.0.0 +VERSION=12.0.1 # Nextcloud tarball checksum sha256 -NEXTCLOUD_SOURCE_SHA256=1b9d9cf05e657cd564a552b418fbf42d669ca51e0fd1f1f118fe44cbf93a243f +NEXTCLOUD_SOURCE_SHA256=5288f645348eddc1a7768825678bd19f110cec585a16f98b52c64389358c74bc # Load common variables and helpers source ./_common.sh From 7a0b6a669d84489191cca24aa55d669f4942f208 Mon Sep 17 00:00:00 2001 From: Rafi59 Date: Tue, 8 Aug 2017 12:44:04 +0200 Subject: [PATCH 02/10] Update upgrade.last.sh --- scripts/upgrade.d/upgrade.last.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/upgrade.d/upgrade.last.sh b/scripts/upgrade.d/upgrade.last.sh index aa30721..e677a8e 100755 --- a/scripts/upgrade.d/upgrade.last.sh +++ b/scripts/upgrade.d/upgrade.last.sh @@ -1,7 +1,7 @@ #!/bin/bash # Version cible de la mise à jour de Nextcloud -VERSION=12.0.1 +VERSION=12.0.0 # Nextcloud tarball checksum sha256 NEXTCLOUD_SOURCE_SHA256=5288f645348eddc1a7768825678bd19f110cec585a16f98b52c64389358c74bc From 46c48fb63648a1fe0ab137731fd53b6313edef54 Mon Sep 17 00:00:00 2001 From: Rafi59 Date: Tue, 8 Aug 2017 12:45:05 +0200 Subject: [PATCH 03/10] Update upgrade.last.sh --- scripts/upgrade.d/upgrade.last.sh | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/scripts/upgrade.d/upgrade.last.sh b/scripts/upgrade.d/upgrade.last.sh index e677a8e..3ac4234 100755 --- a/scripts/upgrade.d/upgrade.last.sh +++ b/scripts/upgrade.d/upgrade.last.sh @@ -1,11 +1,10 @@ #!/bin/bash # Version cible de la mise à jour de Nextcloud -VERSION=12.0.0 +VERSION=12.0.1 # Nextcloud tarball checksum sha256 NEXTCLOUD_SOURCE_SHA256=5288f645348eddc1a7768825678bd19f110cec585a16f98b52c64389358c74bc - # Load common variables and helpers source ./_common.sh From a4d6330eeb57e96c124334152d1825a562d1f89f Mon Sep 17 00:00:00 2001 From: Rafi59 Date: Tue, 8 Aug 2017 12:46:07 +0200 Subject: [PATCH 04/10] Update manifest.json --- manifest.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/manifest.json b/manifest.json index 324f3a3..a56333d 100644 --- a/manifest.json +++ b/manifest.json @@ -8,7 +8,7 @@ }, "url": "https://nextcloud.com", "license": "AGPL-3", - "version": "12.0.0", + "version": "12.0.1", "maintainer": { "name": "-", "email": "-" From ee51bdb1d2271889d370d2650757b5f0462a8c19 Mon Sep 17 00:00:00 2001 From: Rafi59 Date: Tue, 8 Aug 2017 12:46:52 +0200 Subject: [PATCH 05/10] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 09d5889..b15b436 100644 --- a/README.md +++ b/README.md @@ -5,7 +5,7 @@ Nextcloud for YunoHost own data. A personal cloud which run on your own server. With Nextcloud you can synchronize your files over your devices. -**Shipped version:** 12.0.0 +**Shipped version:** 12.0.1 [![Install Nextcloud with YunoHost](https://install-app.yunohost.org/install-with-yunohost.png)](https://install-app.yunohost.org/?app=nextcloud) From 2f3c7e25b325c66c4d6b8549d0d5286f3cbcf327 Mon Sep 17 00:00:00 2001 From: Rafi59 Date: Tue, 8 Aug 2017 14:50:44 +0200 Subject: [PATCH 06/10] Update upgrade.last.sh --- scripts/upgrade.d/upgrade.last.sh | 1 + 1 file changed, 1 insertion(+) diff --git a/scripts/upgrade.d/upgrade.last.sh b/scripts/upgrade.d/upgrade.last.sh index 3ac4234..aa30721 100755 --- a/scripts/upgrade.d/upgrade.last.sh +++ b/scripts/upgrade.d/upgrade.last.sh @@ -5,6 +5,7 @@ VERSION=12.0.1 # Nextcloud tarball checksum sha256 NEXTCLOUD_SOURCE_SHA256=5288f645348eddc1a7768825678bd19f110cec585a16f98b52c64389358c74bc + # Load common variables and helpers source ./_common.sh From 6db2de35f55cf4aee3b57b6258f58aa8bc0bdc4c Mon Sep 17 00:00:00 2001 From: Rafi59 Date: Wed, 9 Aug 2017 15:55:44 +0200 Subject: [PATCH 07/10] [fix] Checksum error --- scripts/upgrade.d/upgrade.last.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/upgrade.d/upgrade.last.sh b/scripts/upgrade.d/upgrade.last.sh index e677a8e..d8874f5 100755 --- a/scripts/upgrade.d/upgrade.last.sh +++ b/scripts/upgrade.d/upgrade.last.sh @@ -4,7 +4,7 @@ VERSION=12.0.0 # Nextcloud tarball checksum sha256 -NEXTCLOUD_SOURCE_SHA256=5288f645348eddc1a7768825678bd19f110cec585a16f98b52c64389358c74bc +NEXTCLOUD_SOURCE_SHA256=1b9d9cf05e657cd564a552b418fbf42d669ca51e0fd1f1f118fe44cbf93a243f # Load common variables and helpers source ./_common.sh From 2154f395b46ccc2249964ba6ccfadcc9cf26750a Mon Sep 17 00:00:00 2001 From: Jimmy Monin Date: Thu, 10 Aug 2017 12:39:23 +0200 Subject: [PATCH 08/10] Fix checksum --- scripts/upgrade.d/upgrade.last.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/upgrade.d/upgrade.last.sh b/scripts/upgrade.d/upgrade.last.sh index 340e8cf..aa30721 100755 --- a/scripts/upgrade.d/upgrade.last.sh +++ b/scripts/upgrade.d/upgrade.last.sh @@ -4,7 +4,7 @@ VERSION=12.0.1 # Nextcloud tarball checksum sha256 -NEXTCLOUD_SOURCE_SHA256=1b9d9cf05e657cd564a552b418fbf42d669ca51e0fd1f1f118fe44cbf93a243f +NEXTCLOUD_SOURCE_SHA256=5288f645348eddc1a7768825678bd19f110cec585a16f98b52c64389358c74bc # Load common variables and helpers source ./_common.sh From cc0126c1459e561d9363e38e47315c40b9c0cc29 Mon Sep 17 00:00:00 2001 From: frju365 Date: Fri, 18 Aug 2017 17:23:53 +0200 Subject: [PATCH 09/10] [Fix] Yunohost Version (Fixes #56) --- manifest.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/manifest.json b/manifest.json index a56333d..9095495 100644 --- a/manifest.json +++ b/manifest.json @@ -20,7 +20,7 @@ "mysql" ], "requirements": { - "yunohost": ">= 2.4.0" + "yunohost": ">= 2.6.0" }, "arguments": { "install" : [ From 769eedfa00eec8d168fabcf620933b08acb57447 Mon Sep 17 00:00:00 2001 From: Jeremy MANSON Date: Wed, 23 Aug 2017 09:13:56 +0200 Subject: [PATCH 10/10] Possible HTTP-Splitting vulnerability (#33) Problem: [http_splitting] Possible HTTP-Splitting vulnerability. Description: Using variables that can contain "\n" may lead to http injection. Additional info: https://github.com/yandex/gixy/blob/master/docs/en/plugins/httpsplitting.md Reason: At least variable "$uri" can contain "\n" --- conf/nginx.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/conf/nginx.conf b/conf/nginx.conf index 82c54ad..19c3d38 100644 --- a/conf/nginx.conf +++ b/conf/nginx.conf @@ -37,7 +37,7 @@ location ^~ #LOCATION# { #rewrite ^/.well-known/host-meta.json #PATH#/public.php?service=host-meta-json last; location #LOCATION# { - rewrite ^ #PATH#/index.php$uri; + rewrite ^ #PATH#/index.php$request_uri; } location = #PATH#/robots.txt {