Dear all,
We have released updates for three older (unsupported) releases to address critical vulnerabilities in versions 2.37 to 2.39.
- GHSA-pwmg-mvjw-4m23: SQL injection vulnerability
- GHSA-3288-cm98-664f: SQL injection vulnerability
→ please note that the above links will not work until the advisories have been made publicly available
Note: these issues can only be exploited by authenticated users.
These updates can be applied by taking the End Of Support (EOS) builds of the relevant versions. You must first be on the final previous release for the version (or a previous EOS build):
FOR 2.37:
- You must be on 2.37.10 (or a previous EOS build)
- You can then update to https://releases.dhis2.org/2.37/dhis2-stable-2.37-eos.war
FOR 2.38:
- You must be on 2.38.7 (or a previous EOS build)
- You can then update to https://releases.dhis2.org/2.38/dhis2-stable-2.38-eos.war
FOR 2.39:
- You must be on 2.39.10.1 (or a previous EOS build)
- You can then update to https://releases.dhis2.org/2.39/dhis2-stable-2.39-eos.war
What is an EOS release?
An EOS (End of Support) release in DHIS2 refers to a new build made available for a version of DHIS2 that is no longer officially supported. These builds are typically released to address critical issues, such as security vulnerabilities, for older versions that have passed their normal support lifecycle. They are not regression tested; but to reduce risk, changes are limited to critical issues.
Thanks!
DHIS2 Release Team