An innovative open source blogging platform developed with ASP.NET 2.0.

BlogEngine.NET Project

Critical Security Patch Available

clock April 14, 2008 23:09 by author Team

Over the weekend, we were alerted to a security flaw in BlogEngine.NET 1.3.0.0.   We have created a new release 1.3.1.0 which corrects this issue and are making a patch available here for users running 1.3.0.0.  For those people running development version of BlogEngine.NET (from the source tab on CodePlex), please note that the latest release 1.3.0.29 has the security fix as well.

The security flaw makes it possible to access BlogEngine.NET user passwords (and other data that you normally would see with a password).  The flaw has been in the system since version 1.2.0.23 and we strongly encourage all BlogEngine.NET users to update to 1.3.1 as soon as possible.  If you see a fellow blogger running something prior to 1.3.0.29 or 1.3.1.0, please let them know to update their site as soon as possible.  In addition, we encourage you to update your BlogEngine.NET password(s) as a security measure after you update.

The BlogEngine.NET team takes security very seriously and we regret that this security issue was introduced into the system.   We hope that no one was seriously effected by the issue and have not heard reports of any to date.  Please update your software as soon as you can.  We are truly sorry for the inconvenience.

It is unfortunate that the issue could not have been handled more discretely.  If you are blogger writing about the issue, we'd hope that you could refrain for spelling out exactly how to attack sites that haven't been updated yet.  (Yes, we do want people to know there is a problem that needs patched, but we'd prefer if were weren't tempting casual hackers to try out the hack on a unpatched site by giving them a step by step guide.)

Again, we are sorry for the inconvenience and any trouble this may have caused you.  If you know of other BlogEngine.NET users, please pass this information along.

Download Full Release: BlogEngine.NET 1.3.1.0

Download Patch for BlogEngine.NET 1.3.0.0


Comments

January 31. 2010 19:12

trackback

Blog Engine.NET Security Patch Available

Blog Engine.NET Security Patch Available

Ryan Lanciaux

February 2. 2010 13:10

trackback

BlogEngine.NET auf die Version 1.4.5 Updaten

BlogEngine.NET auf die Version 1.4.5 Updaten

beqiraj.net

February 3. 2010 12:41

trackback

BlogEngine.NET security update

BlogEngine.NET security update

catlion.name

February 5. 2010 13:26

trackback

BlogEngine.NET: Critical Security Patch Available

BlogEngine.NET: Critical Security Patch Available

scottmarlowe.com

February 13. 2010 04:39

trackback

Upgrade to BlogEngine.NET 1.3.1

Upgrade to BlogEngine.NET 1.3.1

Tanza9's blog

Comments are closed

Sponsor
DiscountASP.NET – BlogEngine.NET Hosting

ImageWhy use BlogEngine.NET?
BlogEngine.NET is a full featured blogging platform that is a breeze to setup, customize, and use. A small download and easy to follow instructions get you up and running in minutes. Pick one of our elegant default themes or make your own theme. Extend the functionality by creating your own custom control or add some of the many built into the system. Read more.