Roundup CVE
This is a list of remediation for CVE’s that are not fixed in the latest release. When the latest release fixes the CVE, see the upgrading doc for these details.
Note
Releases of Roundup from 2.0.0 to 2.5.0 do not check for cross site
request forgeries (CSRF) when using the PATCH method. Release
2.6 fixes this issue. If you are running 2.6.0 you don’t have to do
anything.
Note
If you are running versions 1.6.0 to version 2.5 the filtering of history/journal items does not work correctly if the property is protected by a check function. Release 2.6.0 fixes this. If you are running 2.6.0, you don’t have to do anything.