Hive 2.0.0 has been released with this fix.
For earlier released versions, the workaround of using the additional
hook is available, as described in the CVE.
There might be a 1.2.2 release, but I haven't seen active work or
discussions around that yet.
On Mon, Feb 15, 2016 at 9:09 AM, Adam Robert
Hi, any update on this?
Copying my initial post from a week ago as I don't have the original email
to reply to.
Are there plans to release Hive 1.2.2 with the authorization fix mentioned
in www.openwall.com/lists/oss-security/2016/01/28/12?
The above CVE description mentions "This issue has al