Hi,
The current month of May seems to be one of extremely frequent updates to the Newspaper theme. Envato has sent us update notifications on May 9th, 12th, 20th and now 24th. I am the last one to be complaining about a well maintained product, but integration of the updates in our deployment is in fact time consuming, so some indication about how a specific update should be prioritized would be highly appreciated.
I know that there are concerns about disclosing security related information in public forums. This however means that people will be more likely to miss the urgency of an update and thus be affected from security issues that can always creep up in a complex software project. It will also mean that after three updates in just two weeks, they are becoming tired of diff’ing and analyzing the changes themselves and simply skip the update.
If in fact anybody should be affected by a security issue, missing information on when the issue was discovered and when it was fixed are making forensic analysis quite difficult. Near enough any serious software project I know of provides a detailed change log and release notes for updates and patches.
Wordpress has already been mentioned, Typo3 even chooses security pre-announcements to get people to prepare for a patch release, the same applies to OTRS, Drupal security advisories etc. to name but a few.
Ok, Newspaper is just a theme, not a full fledged CMS. It is software nevertheless, bundling a few external components, and thus falls under the same security considerations as the main CMS.
Not releasing security related information protects no one. Lazy or incompetent customers won’t patch their systems either way, malicious attackers will probably invest the time for analysis of the diffs anyway. I wouldn’t expect details about a security issue, but describing the type of vulnerability (RCE, SQL-Injection, CSS/CSRF, …) and exploitability (anonymous access/registered users only) or some other form of severity assessment would be helpful to those that need to maintain a Newspaper deployment. As would be a patch note that told us that there was no security fix in an update, just bug fixes, so we can decide to roll out the update at the most convenient time.
Kind regards
Markus
Hello Markus,
Unfortunately disclosing the security risk would put all of the theme users that have not yet updated to a major risk as people would know exactly what to do to hack into someone else’s site. That is the reason why the security risks are not released to the public. It is not a major security issue, just a potential risk. We always try to improve the theme and when we discover such vulnerabilities we fix them as soon as possible. The large amount of updates in this period was not foreseen this way. We understand that it may be a bit of a hassle for the user with all these update messages and we are sorry for the inconvenience, but it’s better than the alternative.
Thank you for your understanding.