nixpkgs/pkgs
Maximilian Bosch 0a10c17c8d
hedgedoc: 1.8.2 -> 1.9.0, fixes CVE-2021-39175
ChangeLog: https://github.com/hedgedoc/hedgedoc/releases/tag/1.9.0

As documented in the Nix expression, I unfortunately had to patch
`yarn.lock` manually (the `yarn.nix` result isn't affected by this). By
adding a `git+https`-prefix to
`midi "https://github.com/paulrosen/MIDI.js.git#abcjs"` in the lock-file
I ensured that `yarn` actually uses the `MIDI.js` from the offline-cache
from `yarn2nix` rather than trying to download a tarball from GitHub.

Also, this release contains a fix for CVE-2021-39175 which doesn't seem
to be backported to 1.8. To quote NVD[1]:

> In versions prior to 1.9.0, an unauthenticated attacker can inject
> arbitrary JavaScript into the speaker-notes of the slide-mode feature
> by embedding an iframe hosting the malicious code into the slides or by
> embedding the HedgeDoc instance into another page.

Even though it "only" has a medium rating by NVD (6.1), this seems
rather problematic to me (also, GitHub rates this as "High"), so it's
actually a candidate for a backport.

[1] https://nvd.nist.gov/vuln/detail/CVE-2021-39175
2021-09-19 00:18:18 +02:00
..
applications wasabibackend: Fix create_deps.sh script and update dependencies 2021-09-17 10:11:27 -07:00
build-support bintools-wrapper: check if bintools to wrap isGNU, not stdenv 2021-09-17 17:06:24 +02:00
common-updater
data Merge master into staging-next 2021-09-13 00:01:41 +00:00
desktops xorg.xf86*: fix include dir 2021-09-16 00:42:24 +08:00
development python-language-server: Update dependencies 2021-09-17 10:11:27 -07:00
games osu-lazer: Update dependencies 2021-09-17 10:11:27 -07:00
misc ryujinx: Update dependecies 2021-09-17 10:11:27 -07:00
os-specific linux/hardened/patches/5.4: 5.4.146-hardened1 -> 5.4.147-hardened1 2021-09-17 09:02:31 -04:00
pkgs-lib
servers hedgedoc: 1.8.2 -> 1.9.0, fixes CVE-2021-39175 2021-09-19 00:18:18 +02:00
shells oh-my-zsh: 2021-09-10 → 2021-09-15 2021-09-16 09:16:58 +00:00
stdenv
test
tools discordchatexporter-cli: Update dependencies 2021-09-17 10:11:27 -07:00
top-level steam-acf: init at 0.1.0 2021-09-17 18:49:01 +02:00