Skip to content

Add RELEASE-NOTES.md [JIRA: TOOLS-248]#200

Merged
nickelization merged 3 commits into
developfrom
dr/release_notes_3.0
Mar 21, 2016
Merged

Add RELEASE-NOTES.md [JIRA: TOOLS-248]#200
nickelization merged 3 commits into
developfrom
dr/release_notes_3.0

Conversation

@JeetKunDoug
Copy link
Copy Markdown
Contributor

With recent security/permissions changes, need to bump to 3.0.0. Included upgrade/update nodes for users and packagers.

@nickelization
Copy link
Copy Markdown
Contributor

👍 1bc15c3 - lgtm!

Comment thread RELEASE-NOTES.md Outdated
## Security Improvements
### Introduction
### Security Advisory dated March 1, 2016
It was [recently reported](http://docs.basho.com/riak/latest/community/product-advisories/codeinjectioninitfiles/) that, if a user could gain access to the `riak` user (or, in node_package parlance, the `package_install_user`), that use would then have write access to init scripts that are generally run as `root`, exposing an escalation of privileges attack where said use could then get the `root` user to execute a script that could allow the original user to become `root` on the system.
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

use -> user (also that -> the to avoid the that that problem): "...package_install_user), the user would then have write access to init scripts that are generally run as root, exposing an escalation of privileges attack where said user could then ..."

@lrnrthr
Copy link
Copy Markdown

lrnrthr commented Mar 21, 2016

Made some comments w/ changes. Outside of those, 👍

@lrnrthr
Copy link
Copy Markdown

lrnrthr commented Mar 21, 2016

👍 to the updates

@bashopatricia
Copy link
Copy Markdown

create jira issue

@Basho-JIRA Basho-JIRA changed the title Add RELEASE-NOTES.md Add RELEASE-NOTES.md [JIRA: TOOLS-248] Mar 21, 2016
nickelization added a commit that referenced this pull request Mar 21, 2016
Add RELEASE-NOTES.md [JIRA: TOOLS-248]
@nickelization nickelization merged commit c630bcb into develop Mar 21, 2016
@hazen hazen deleted the dr/release_notes_3.0 branch March 21, 2016 20:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants