diff options
author | Unknwon <u@gogs.io> | 2017-01-03 10:36:27 +0800 |
---|---|---|
committer | Unknwon <u@gogs.io> | 2017-01-03 10:36:27 +0800 |
commit | 8aa35577b3267d6d23cfe2fbda180b1c53da5881 (patch) | |
tree | e700ffc9b07a74d86e698ac2607b8ad584e9150b | |
parent | c4086d43dbfaf0dc1c9e72e84498005da8762421 (diff) |
Fix vulnerability reported in #4006
-rw-r--r-- | README.md | 2 | ||||
-rw-r--r-- | gogs.go | 2 | ||||
-rw-r--r-- | routers/repo/pull.go | 2 | ||||
-rw-r--r-- | templates/.VERSION | 2 |
4 files changed, 4 insertions, 4 deletions
@@ -3,7 +3,7 @@ Gogs - Go Git Service [ -##### Current tip version: 0.9.114 (see [Releases](https://github.com/gogits/gogs/releases) for binary versions ~~or submit a task on [alpha stage automated binary building system](https://build.gogs.io/)~~) +##### Current tip version: 0.9.115 (see [Releases](https://github.com/gogits/gogs/releases) for binary versions ~~or submit a task on [alpha stage automated binary building system](https://build.gogs.io/)~~) | Web | UI | Preview | |:-------------:|:-------:|:-------:| @@ -17,7 +17,7 @@ import ( "github.com/gogits/gogs/modules/setting" ) -const APP_VER = "0.9.114.1227" +const APP_VER = "0.9.115.0103" func init() { runtime.GOMAXPROCS(runtime.NumCPU()) diff --git a/routers/repo/pull.go b/routers/repo/pull.go index 4f0ef1ed..1348c7de 100644 --- a/routers/repo/pull.go +++ b/routers/repo/pull.go @@ -49,7 +49,7 @@ func getForkRepository(ctx *context.Context) *models.Repository { return nil } - if !forkRepo.CanBeForked() { + if !forkRepo.CanBeForked() || !ctx.Repo.HasAccess() { ctx.Handle(404, "getForkRepository", nil) return nil } diff --git a/templates/.VERSION b/templates/.VERSION index 1bc48f34..5014f536 100644 --- a/templates/.VERSION +++ b/templates/.VERSION @@ -1 +1 @@ -0.9.114.1227
\ No newline at end of file +0.9.115.0103
\ No newline at end of file |