3 ms·
Admin and developer of two Magento based sites here. Magento has just started posting notifications of these vulnerabilities in their notification center. The
by jay-saint 11y ago
Admin and developer of two Magento based sites here.
Magento has just started posting notifications of these vulnerabilities in their notification center. They sent two messages. One on April 16 and another on April 19. See images of message here http://imgur.com/a/edVGy http://imgur.com/a/edVGy they did inform us that a press release with the vulnerability was coming.
That said I am annoyed that the patch was from February 2015 and October 2014. If you do not go to this page https://www.magentocommerce.com/products/downloads/magento/ https://www.magentocommerce.com/products/downloads/magento/
on a regular basis there is no way that I know of to get same day notification of new patches.
- jay-saint 11y agoOne extra note for those who may run their Magento install on a shared host. You will likely not be able to use the patch as is. It is distributed as .sh file that requires SSH and permissions that are not available on most shared hosts. This is a serious shortfall of this patching method. You should create a trouble ticket with support and they should be able to run the patch scripts for you.
- teh_klev 11y agoI agree for the most part here. But it's not totally insurmountable. Patch against your local development and/or staging copy then upload the changed files to your shared host.
- benmarks 11y agoDoing my best to get a 100% marketing-free mailing list for notifications in place soon.