It is basically the same vulnerability exploited with a different socket call. The initial fix in 2.6.1 only prevented a specific case, the fix in 2.8.1 should cover all cases.
You can either upgrade to 2.8.1 or only get the changes from the specific commit.
Any release date planned for 1.17.0?
Unsolved
NodeBB Development
-
1.17 when will it be released?
-
@onur-baran Same as it ever was.... When it's ready. And hopefully not before.
Sorry, just couldn't resist.
But dinnae fash yersel... some body more knowledgeable than I will be comin' along this trail.