From f5981e6ef381d5c4be33e0725cdb697a5515ca7b Mon Sep 17 00:00:00 2001 From: Martin Cech Date: Tue, 24 Oct 2017 12:28:11 -0400 Subject: [PATCH] add tldr for security --- doc/source/releases/17.09_announce.rst | 43 +++++++++++++++++++------- 1 file changed, 31 insertions(+), 12 deletions(-) diff --git a/doc/source/releases/17.09_announce.rst b/doc/source/releases/17.09_announce.rst index 2a536dad649..8fc81c94461 100644 --- a/doc/source/releases/17.09_announce.rst +++ b/doc/source/releases/17.09_announce.rst @@ -45,10 +45,33 @@ See `the community hub `__ for a Security ======== -Together with the 17.09 Galaxy version we release the following three security patches. Per our `Security Policy `__ these has been already applied to all Galaxy releases in the last 12 months. +The 17.09 Galaxy version includes four security patches. Per our `Security Policy `__ these has been already applied to all Galaxy releases in the last 12 months. + +For the best security we recommend all deployers to update to the latest release. If you maintain a publicly accessible Galaxy please consider signing up for this [mailing list](https://lists.galaxyproject.org/listinfo/galaxy-public-servers) to receive the future security patches in advance of the public disclosure. +Details of the patched vulnerabilities can be found in the `Security patch details`_ section of these release notes. + +Deprecation Notices +=================== + +* The Galaxy Sample Tracking and External Services functionality is now considered deprecated. In future releases we will strip down the related + user interface and introduce configuration option to keep relevant API controllers active if desired. `Related PR `__. +* The deprecated admin-only interface for Galaxy Data Libraries is staged to be removed in the next release. +* Workflows API: When exposing WorkflowInvocationSteps ``state`` will no longer be available. +* The ``refresh_on_change`` attribute of a ```` tag in the tool syntax can no longer be set to a value of another parameter. Use boolean instead (e.g.``refresh_on_change="True"``). `Details `__ + + +Release Notes +=========================================================== + +.. include:: 17.09.rst + :start-after: announce_start + +Security patch details +====================== + Limited Galaxy Data Library unauthorized filesystem access ---------------------------------------------------------- @@ -110,20 +133,16 @@ access to read on the host(s) where jobs run. The fix for this issue has been applied to Galaxy releases back to 16.07 and can be found in this `commit `__ -Deprecation Notices -=================== +Cross site scripting and session fixation +----------------------------------------- -* The Galaxy Sample Tracking and External Services functionality is now considered deprecated. In future releases we will strip down the related - user interface and introduce configuration option to keep relevant API controllers active if desired. `Related PR `__. -* The deprecated admin-only interface for Galaxy Data Libraries is staged to be removed in the next release. -* Workflows API: When exposing WorkflowInvocationSteps ``state`` will no longer be available. -* The ``refresh_on_change`` attribute of a ```` tag in the tool syntax can no longer be set to a value of another parameter. Use boolean instead (e.g.``refresh_on_change="True"``). `Details `__ +Disclosed on the `mailing list `__ in August 2017. +Vulnerabilities were found by Eric Rasche and Manabu Ishii respectively. Detailed descriptions of these categories of vulnerabilities can be found at: -Release Notes -=========================================================== +- https://www.owasp.org/index.php/Cross-site_Scripting_(XSS) +- https://www.owasp.org/index.php/Session_fixation -.. include:: 17.09.rst - :start-after: announce_start +The fix for these issues has been applied to Galaxy releases back to 16.10 and can be found in this `diff `__ .. include:: _thanks.rst