Forum archive
Redmine Security Vulnerability
Since there is a critical Ruby on Rails vulnerability in Redmine 2.2.3, shouldn't the official Redmine app be updated to the current stable version of Redmine?
http://www.redmine.org/projects/redmine/wiki/Security_Advisories
The whole TurnKey library really needs a refresh. We actually are well overdue for our maintenance release but unfortunately some urgent 'behind-the-scenes' stuff has taken our attention.
Anyway, thanks for reporting and I see that you have found the update thread that a community member kindly posted. Also I have lodged a bug report on the TurnKey Issue Tracker. Like I said we're overdue for a refresh anyway, but this is another issue that adds to the importance of this happening ASAP. (Unfortuantely though, no idea of ETA).