Recent security update: Is unattended *upgrades* a...
# help-with-umbraco
k
Announcement says "unattended install" is a sufficient workaround for the security issue. But is unattended upgrades sufficient? **EDIT**: TLDR: No, unattended installations need to be enabled.
10.6.1, 11.4.2, 12.0.1.
> Enabling the Unattended Install feature will mean the vulnerability is not exploitable.
s
Actually yes, the problem happens when you get into an install state, unattended installs prevent you from getting into that state.
k
We haven't actually enabled unattended installations, only unattended upgrades. Is that sufficient? So technically, we have unattended installs disabled, but unattupgrades enabled.
s
Yeah it requires unattended installs enabled
k
Also, is U8 safe? Asking for a friend.
s
You can read the advisory for what is not safe 😉
Also, if you do enable unattended installs, you'll need to deploy that live anyway. I'd advise to do the upgrade to the latest patch instead, should be painless.
k
Not from 8.10... 🤣
Thanks. We'll keep upgrading!
s
> Versions affected: Umbraco 10.0.0-10.6.0, 11.0.0-11.4.1. and Umbraco 12.0.0 Conclusion: don't worry about v8
k
I saw that of course, but it also says that 9 is likely affected. Yeah, 8 has plenty of other worries already
s
If we don't mention 8 then it's because there's nothing to mention 😅 We didn't mention v4 either 😛
k
I think v7 is the first one I used...
7 Views