You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
There are several critical vulnerabilities in the current production version of Matomo (5.2.2) due to its dependency on TCPDF version 6.7. The following CVEs have been identified as high or critical:
CVE-2024-56527
These vulnerabilities pose significant security risks, potentially affecting data integrity and server security. Given the severity, I recommend considering an expedited release of version 5.2.3 with an upgraded TCPDF to version 6.8, as already proposed in PR [automatic composer updates] #22906.
Considering that the milestone for version 5.3 is approximately 75-80% complete, is there an opportunity to release Matomo 5.2.3 with the necessary TCPDF update to mitigate these vulnerabilities promptly?
Thank you for addressing this critical issue.
The text was updated successfully, but these errors were encountered:
There are several critical vulnerabilities in the current production version of Matomo (5.2.2) due to its dependency on TCPDF version 6.7. The following CVEs have been identified as high or critical:
These vulnerabilities pose significant security risks, potentially affecting data integrity and server security. Given the severity, I recommend considering an expedited release of version 5.2.3 with an upgraded TCPDF to version 6.8, as already proposed in PR [automatic composer updates] #22906.
Considering that the milestone for version 5.3 is approximately 75-80% complete, is there an opportunity to release Matomo 5.2.3 with the necessary TCPDF update to mitigate these vulnerabilities promptly?
Thank you for addressing this critical issue.
The text was updated successfully, but these errors were encountered: