Browse Source

Fix vulnerability reported in #4006

Unknwon 8 years ago
parent
commit
8aa35577b3
4 changed files with 4 additions and 4 deletions
  1. 1 1
      README.md
  2. 1 1
      gogs.go
  3. 1 1
      routers/repo/pull.go
  4. 1 1
      templates/.VERSION

+ 1 - 1
README.md

@@ -3,7 +3,7 @@ Gogs - Go Git Service [![Build Status](https://travis-ci.org/gogits/gogs.svg?bra
 
 ![](https://github.com/gogits/gogs/blob/master/public/img/gogs-large-resize.png?raw=true)
 
-##### Current tip version: 0.9.114 (see [Releases](https://github.com/gogits/gogs/releases) for binary versions ~~or submit a task on [alpha stage automated binary building system](https://build.gogs.io/)~~)
+##### Current tip version: 0.9.115 (see [Releases](https://github.com/gogits/gogs/releases) for binary versions ~~or submit a task on [alpha stage automated binary building system](https://build.gogs.io/)~~)
 
 | Web | UI  | Preview  |
 |:-------------:|:-------:|:-------:|

+ 1 - 1
gogs.go

@@ -17,7 +17,7 @@ import (
 	"github.com/gogits/gogs/modules/setting"
 )
 
-const APP_VER = "0.9.114.1227"
+const APP_VER = "0.9.115.0103"
 
 func init() {
 	runtime.GOMAXPROCS(runtime.NumCPU())

+ 1 - 1
routers/repo/pull.go

@@ -49,7 +49,7 @@ func getForkRepository(ctx *context.Context) *models.Repository {
 		return nil
 	}
 
-	if !forkRepo.CanBeForked() {
+	if !forkRepo.CanBeForked() || !ctx.Repo.HasAccess() {
 		ctx.Handle(404, "getForkRepository", nil)
 		return nil
 	}

+ 1 - 1
templates/.VERSION

@@ -1 +1 @@
-0.9.114.1227
+0.9.115.0103