#Todays security update
1 messages · Page 1 of 1 (latest)
It will not come back, we only keep a fallback beta that is 1 version behind the latest unstable version. Meaning 42.13.2 would be removed soon any due to an upcoming patch, but the security problem forced our hand to remove it sooner.
At the moment, both outdatedunstable and unstable are on the same version, once the next patch releases, Unstable will be updated to the latest, while outdatedunstable will stay on 42.14
The same thing would have happened even without the security patch
alr, thank you
https://theindiestone.com/forums/index.php?/topic/92297-addressing-a-security-vulnerability/
The post on RCE vuln doesn't state which specific versions are affected. Can we have an update on this?
We need info on which specific versions of the game are affected, so people can easily tell if they need to bump the version of the server.
As many of you have noticed, a number of the builds have disappeared from the Game Versions & Betas tab on Steam. Yesterday we were made aware of a significant security vulnerability in the game thanks to one of our modders who responsibly reported the issue to us. It's worth noting that this...
Is the vuln currently fixed? Which versions are safe?
There was no RCE vulnerability that would affect us, it was unrelated to Java
All versions that are currently selectable as Betas on Steam are unaffected, they already have the security patch
If you were on previous versions, or have a server that is outdated before the update, you should bump the version