#3189 closed task (fixed)
Upgrade Nexus to v3.68.1 or later
Reported by: | juanluisrp | Owned by: | robe |
---|---|---|---|
Priority: | critical | Milestone: | Sysadmin Contract 2024-I |
Component: | SysAdmin/Repo | Keywords: | |
Cc: |
Description
A critical security vulnerability has been discovered in Nexus (CVE-2024-4956). The vulnerability has been fixed in Nexus v3.68.1.
Change History (11)
comment:1 by , 7 months ago
Owner: | changed from | to
---|
comment:2 by , 7 months ago
Milestone: | Unplanned → Sysadmin Contract 2024-I |
---|
comment:3 by , 7 months ago
comment:5 by , 7 months ago
Thanks, does anyone have time to rotate credentials (secrets / passwords)?
comment:6 by , 7 months ago
There are 4 build server users to contact ...
- postgisbuild
- gsdocker
- gsbuild
- gnbuild
comment:7 by , 7 months ago
I have sent email to the respective contact people for those build users. Not sure if we can do anything more than that?
If we feel more strongly I could reset the passwords (breaking the build servers) and wait for the respective teams to contact us?
Note:
See TracTickets
for help on using tickets.
Will start the process of upgrade shortly