• Get Review Board
  • What's New
  • Products
  • Review Board Code review, image review, and document review
  • Documentation
  • Release Notes
  • Power Pack Enterprise integrations, reports, and enhanced document review
  • Try for 60 Days
  • Purchase
  • RBCommons Review Board as a Service, hosted by us
  • Pricing
  • RBTools Command line tools and Python API for Review Board
  • Documentation
  • Release Notes
  • Review Bot Automated code review, connecting tools you already use
  • Documentation
  • Release Notes
  • RB Gateway Manage Git and Mercurial repositories in your network
  • Documentation
  • Release Notes
  • Learn and Explore
  • What is Code Review?
  • Documentation
  • Frequently Asked Questions
  • Support Options
  • Third-Party Integrations
  • Demo
  • Review Board Security/Bug Fix Releases: 6.0.2, 5.0.7, 4.0.13, 3.0.26

    January 16, 2024

    Today's releases fix an important security vulnerability we've found in-house, and improve stability overall in Review Board 6.

    API Security Fix

    We discovered a security issue with two of our APIs while performing an in-house performance audit of our code. This allows a user with legitimate access to a Review Board server to craft a specific API request that returns diff content they wouldn't normally have permission to access (draft diffs or published diffs associated with a private repository or invite-only review group).

    Users cannot exploit this bug without legitimate access to the Review Board server (or the Local Site server partition, if used).

    We aren't aware of this vulnerability being used in the wild. It requires making use of an optional header when accessing these APIs, plus knowledge of internal database APIs for published diffs.

    As part of fixing this security issue, we've done the following:

    1. We sent patches (and custom builds as needed) to our customers with Premium Support contracts.
    2. We audited the remainder of our APIs. This type of issue was not found anywhere else.
    3. We improved our testing infrastructure so that this type of issue would be found automatically going forward.

    We recommend that everyone upgrade to the appropriate release of Review Board.

    Review Board 6 Stability

    We've addressed a few regressions introduced in Review Board 6.0:

    • Manually uploading diffs (either to new or existing review requests) should now work on all types of repositories.
    • Batch publishing will now work when using Local Site server partitions.
    • Empty reviews will no longer be posted if creating a review, leaving comments, and then deleting the comments.
    • Switching between search engine backends no longer require restarting the web server.
    • Logging in from the Log Out page now takes you to the dashboard, instead of logging you back out.
    • Some minor UI issues in the Administration UI have been fixed.

    Upgrading

    If you're using our official releases, follow the upgrade instructions in the release notes below:

    • Review Board 6.0.2
    • Review Board 5.0.7
    • Review Board 4.0.13
    • Review Board 3.0.26

    If you're using releases provided by your Linux distribution or a third-party, you will need to inquire with them about your upgrade options and support.

    If you need assistance with your server, we can help under a support contract. This entitles you to on-going support for your server, custom builds, backported fixes, pre-release security patches, and solutions tailored for your company's needs.

    Keep up with the latest Review Board releases, security updates, and helpful information.

    About
    News
    Demo
    RBCommons Hosting
    Integrations
    Happy Users
    Support Options
    Documentation
    FAQ
    User Manual
    RBTools
    Administration Guide
    Power Pack
    Release Notes
    Downloads
    Review Board
    RBTools
    Djblets
    Power Pack
    Package Store
    PGP Signatures
    Contributing
    Bug Tracker
    Submit Patches
    Development Setup
    Wiki
    Follow Us
    Mailing Lists
    Reddit
    Twitter
    Mastodon
    Facebook
    YouTube

    Copyright © 2006-2025 Beanbag, Inc. All rights reserved.

    Terms of Service — Privacy Policy — AI Ethics Policy — Branding