Previous work: T305209: Write and send supplementary release announcement for extensions and skins with security patches (1.35.7/1.37.3/1.38.2)
| Maniphest ID | Extension or Skin | CVE ID | REL1_35 | REL1_37 | REL1_38 | REL1_39 | master |
|---|---|---|---|---|---|---|---|
| T308861 | OAuth | CVE-2022-39191 | Yes | Yes | Yes | Yes | Yes |
| T313205 | Growth Experiments | CVE-2022-39194 | N/A - not affected | Yes | Yes | Yes | Yes |
| T310763 | IPInfo | CVE-2022-39192 | N/A - no branch | Yes | Yes | Yes | Yes |
| T314245 | PageTriage | CVE-2022-41344 | Yes | Yes | Yes | Yes | Yes |
| T312820 | OAuth | CVE-2022-41346 | N/A | Yes | Yes | Yes | Yes |
| T302479 | Translate | CVE-2022-41345 | N/A | N/A | N/A | Yes | Yes |
Notes
- Due to an issue with an OAuth dependency breaking tests in CI (T279837), the following OAuth patches within this security release were force-merged: