about summary refs log tree commit diff
diff options
context:
space:
mode:
authorMartin Weinelt <hexa@darmstadt.ccc.de>2023-02-01 14:05:42 +0100
committerMartin Weinelt <hexa@darmstadt.ccc.de>2023-02-01 14:29:43 +0100
commit98c6798b10247ada432dca92ef5ca47d877ea23a (patch)
tree11939f5b6c691caf5e6d9a46d4299397442291bb
parent1efc432d4f72c0e3146c1dd2e8a3ffa705be8a04 (diff)
wallabag: 2.5.2 -> 2.5.3
https://github.com/wallabag/wallabag/releases/tag/2.5.3

Fixes two security issues, were an authorized user could
- export other users entries
- modify or delete other user's annotations

Fixes: CVE-2023-0609, CVE-2023-0610
-rw-r--r--pkgs/servers/web-apps/wallabag/default.nix8
1 files changed, 6 insertions, 2 deletions
diff --git a/pkgs/servers/web-apps/wallabag/default.nix b/pkgs/servers/web-apps/wallabag/default.nix
index 955eac2c6c334..4fb9c43380da3 100644
--- a/pkgs/servers/web-apps/wallabag/default.nix
+++ b/pkgs/servers/web-apps/wallabag/default.nix
@@ -16,7 +16,7 @@
 
 let
   pname = "wallabag";
-  version = "2.5.2";
+  version = "2.5.3";
 in
 stdenv.mkDerivation {
   inherit pname version;
@@ -27,7 +27,7 @@ stdenv.mkDerivation {
       "https://static.wallabag.org/releases/wallabag-release-${version}.tar.gz"
       "https://github.com/wallabag/wallabag/releases/download/${version}/wallabag-${version}.tar.gz"
     ];
-    hash = "sha256-Q989SorGPm3KBuQhGAinYU6HGIa9RrhtRPvwGALU6jk=";
+    hash = "sha256-a30z9rdXcfc2eVuShEobgDWWHr9TfMwq9WwaWdrI3QU=";
   };
 
   patches = [
@@ -45,8 +45,12 @@ stdenv.mkDerivation {
   dontBuild = true;
 
   installPhase = ''
+    runHook preInstall
+
     mkdir $out
     cp -R * $out/
+
+    runHook postInstall
   '';
 
   meta = with lib; {