opensolutions / ViMbAdmin

Virtual Mailbox Administration
http://www.vimbadmin.net/
GNU General Public License v3.0
485 stars 101 forks source link

Don't expose ViMbAdmin's patch level in the footer #299

Closed PhrozenByte closed 1 year ago

PhrozenByte commented 1 year ago

Exposing the exact patch level allows attackers to easily identify likely vulnerable instances of ViMbAdmin if a security flaw happens to be found. This commit simply replaces the exact version string ('3.3.0') with the milestone version string ('3.3') in ViMbAdmin's footer. See 013cfec60b4900c661e1cc75b20d28b6a377f8ee

Additional changes:

barryo commented 1 year ago

Merged with minor change - keeping full version for admins.