Magento version 1.0.19870.1 is now available

We have just released Magento version 1.0.19870.1 that includes a patch for the Base URL security issue described in detail the the blog post here.

This patch adds validation and a warning message in the admin panel if the configuration value for Base URL is {{base_url}}. The installation wizard was modified so it requests a valid Base URL value during the installation process.

There are no other updates in this version.

If you are using Magento version 1.0.19870 or lower we highly recommend upgrading to Magento version 1.0.19870.1

Instructions for Upgrading Magento with a full package, via SVN, via the MagentoConnect Manager and using SSH shell access are available in this wiki post.

RSS comments feed for this entry

User Comments

|6 comments
  1. Ross

    1Ross from Scarborough, North Yorkshire, UK|posted May 22 2008

    Well done for making this available via Magento Connect.

  2. Did

    2Did from Paris, France|posted May 22 2008

    It worked like a charm..Thanks

  3. ben-zene

    3ben-zene |posted May 23 2008

    I would love to see a patch for this as well as the whole new release, or at least know what files have changed without having to do a full diff.  Any possibility of including that info in your update posts or the wiki/changelog?

  4. camouflageX

    4camouflageX |posted May 23 2008

    I agree, a patch for small security updates would be nice.

  5. YoavKutner

    5YoavKutner |posted May 23 2008

    @ben-zene - We will try and have this in future releases.

    In this case there is no real need to upgrade if you correct your configuration in the way described in the blog post.

    Thanks

    yoav

  6. harry12bar

    6harry12bar |posted June 2 2008

    I did and my emails stopped working.... anyones emails working? i need to know just to see if it just my upgrade… reaaly close to release but now set back . Really need help guys.
    Thx


RSS: This Entry| All Blog Posts (RSS)