• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
      • VaultWiki News
      • Visit the Wiki
    • Forum
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Home
    • VaultWiki Security Update: July 2017

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    • VaultWiki Security Update: July 2017

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on August 6, 2017 2:51 PM
      2 Comments Comments
      As of August 6, 2017, the July 2017 security patches for currently supported versions of VaultWiki 4.x are available.

      Issue List

      VWE-2017-3857 is a Permissions Escalation involving custom user masks and custom moderator permissions, where "No" and "Never" values that were part of the mask did not take precedence over inherited "Yes" values. The issue affects several Patch Level releases of the VaultWiki 4.x series since 4.0.8, and all versions since 4.0.16.

      VWE-2017-3858 is a Permissions Escalation involving an incorrect notification that setting all settings to "Not Set" for custom permissions, user masks, or moderator permissions was successful, even when the change could not be successfully saved. In this case, existing "Yes" values will still be in effect, even though the administrator believes that they have been revoked. The issue affects VaultWiki 4.0.12 and higher.

      Patches

      The following patches, issued August 6, 2017, address the aforementioned issues:
      • 4.0.18 Patch Level 1
      • 4.0.17 Patch Level 3
      • 4.0.16 Patch Level 4
      • 4.0.15 Patch Level 8
      • 4.0.14 Patch Level 11
      • 4.0.13 Patch Level 11


      We highly recommend that all users running VaultWiki 4.x in a production environment update to a patched release.
      Comments 2 Comments
      1. Alfa1 - August 10, 2017
        • Reply
        Is 4.0.19 not secure?
      1. pegasus - August 23, 2017
        • Reply
        4.0.19 is not affected by these issues. It was actually released after these patches.

      Oops!

       
      Cancel Changes
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 6:55 PM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2025 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
    Copyright © 2008 - 2024 VaultWiki Team, Cracked Egg Studios, LLC.