We've just released Conductance 0.5, Stratifiedjs 0.19 and an important Conductance security fix - see blog for details: http://onilabs.com/blog/oni-conductance-0.5-and-a-security-fix
Oni Labs: Conductance 0.5 and a security fix
The bad news first: Just after cutting a new 0.5.0 release of Conductance, we discovered a security issue in all versions of Conductance which allows a remote attacker to execute arbitrary code on a server which publishes an .api module, by exploiting custom object marshallers.
no plus ones
Add a comment...