From 151f2babd8e498b4f3e93bc71cf13c9e5b33c18e Mon Sep 17 00:00:00 2001 From: Armin Schrenk Date: Mon, 7 Aug 2023 10:02:39 +0200 Subject: [PATCH 1/4] Add NoProfile option to powershell scripts run during windows instaler Closes #GHSA-62gx-54j7-mjh3 --- dist/win/contrib/patchWebDAV.bat | 2 +- dist/win/contrib/version170-migrate-settings.bat | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/dist/win/contrib/patchWebDAV.bat b/dist/win/contrib/patchWebDAV.bat index aad226881..cc9f667dd 100644 --- a/dist/win/contrib/patchWebDAV.bat +++ b/dist/win/contrib/patchWebDAV.bat @@ -3,5 +3,5 @@ ::REPLACE ME cd %~dp0 -powershell -NoLogo -NonInteractive -ExecutionPolicy Unrestricted -Command .\patchWebDAV.ps1^ +powershell -NoLogo -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -Command .\patchWebDAV.ps1^ -LoopbackAlias %LOOPBACK_ALIAS% \ No newline at end of file diff --git a/dist/win/contrib/version170-migrate-settings.bat b/dist/win/contrib/version170-migrate-settings.bat index 94ec16dac..345b01ad9 100644 --- a/dist/win/contrib/version170-migrate-settings.bat +++ b/dist/win/contrib/version170-migrate-settings.bat @@ -2,4 +2,4 @@ :: see comments in file ./version170-migrate-settings.ps1 cd %~dp0 -powershell -NoLogo -NonInteractive -ExecutionPolicy Unrestricted -Command .\version170-migrate-settings.ps1 \ No newline at end of file +powershell -NoLogo -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -Command .\version170-migrate-settings.ps1 \ No newline at end of file From d939e91661ca01f128714ac5b2f68edbf070faa6 Mon Sep 17 00:00:00 2001 From: Armin Schrenk Date: Mon, 7 Aug 2023 10:04:08 +0200 Subject: [PATCH 2/4] prepare 1.9.3 --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 467a40ed3..ed07c2287 100644 --- a/pom.xml +++ b/pom.xml @@ -3,7 +3,7 @@ 4.0.0 org.cryptomator cryptomator - 1.9.2 + 1.9.3 Cryptomator Desktop App From 9ae9473b952025b1c1f784eb9d3433ff24614f81 Mon Sep 17 00:00:00 2001 From: Armin Schrenk Date: Mon, 7 Aug 2023 10:19:04 +0200 Subject: [PATCH 3/4] finalize 1.9.3 --- dist/linux/common/org.cryptomator.Cryptomator.metainfo.xml | 1 + 1 file changed, 1 insertion(+) diff --git a/dist/linux/common/org.cryptomator.Cryptomator.metainfo.xml b/dist/linux/common/org.cryptomator.Cryptomator.metainfo.xml index 4fd30d14f..0ca6499ad 100644 --- a/dist/linux/common/org.cryptomator.Cryptomator.metainfo.xml +++ b/dist/linux/common/org.cryptomator.Cryptomator.metainfo.xml @@ -66,6 +66,7 @@ + From da21c7fa809f61292d88895d45a4a4a3b4487c0d Mon Sep 17 00:00:00 2001 From: Armin Schrenk Date: Fri, 4 Aug 2023 17:01:19 +0200 Subject: [PATCH 4/4] suppress false positive cherry picked from 9bd5b45ea7ef8157efbcff416fcfe18c47002de7 --- suppression.xml | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/suppression.xml b/suppression.xml index b7e99d589..7d4e37970 100644 --- a/suppression.xml +++ b/suppression.xml @@ -63,4 +63,11 @@ CVE-2023-35116 - \ No newline at end of file + + + ^pkg:maven/org\.apache\.jackrabbit/jackrabbit\-webdav@.*$ + CVE-2023-37895 + +