<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>CRIN Trac: Ticket #25: Piwik 2.14.0</title>
    <link>https://trac.crin.org/trac/ticket/25</link>
    <description>&lt;p&gt;
A new version of Piwik will be out very soon (probably best to wait for the full release, there is a release candidate out today) which fixes critical security issues - upgrading should take no more than 15 mins, would you like your site upgraded?
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Three security issues have been fixed. We are grateful for security researchers who responsibly disclosed these security issues to us: Abdullah Hussam Gazi (CSRF issue) and Dmitriy Shcherbatov (two XSS issues).
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://piwik.org/changelog/piwik-2-14-0/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://piwik.org/changelog/piwik-2-14-0/&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
    <language>en-us</language>
    <image>
      <title>CRIN Trac</title>
      <url>https://trac.crin.org/trac/chrome/site/logo.gif</url>
      <link>https://trac.crin.org/trac/ticket/25</link>
    </image>
    <generator>Trac 1.0.2</generator>
    <item>
      
        <dc:creator>gillian</dc:creator>

      <pubDate>Wed, 24 Jun 2015 11:15:03 GMT</pubDate>
      <title></title>
      <link>https://trac.crin.org/trac/ticket/25#comment:1</link>
      <guid isPermaLink="false">https://trac.crin.org/trac/ticket/25#comment:1</guid>
      <description>
        &lt;pre class="wiki"&gt;Hi Chris,
Yes please to upgrade Piwik if it's for critical security issues.
Best,
Gillian
On 24 June 2015 at 09:46, CRIN Trac &amp;lt;trac@trac.crin.org&amp;gt; wrote:
&amp;gt; #25: Piwik 2.14.0
&amp;gt; --------------------------------+-----------------------------------------
&amp;gt;            Reporter:  chris     |                      Owner:  chris
&amp;gt;                Type:  defect    |                     Status:  new
&amp;gt;            Priority:  critical  |                  Milestone:  Maintenance
&amp;gt;           Component:  piwik     |                    Version:
&amp;gt;            Keywords:            |  Estimated Number of Hours:  0.25
&amp;gt; Add Hours to Ticket:  0         |                  Billable?:  1
&amp;gt;         Total Hours:  0         |
&amp;gt; --------------------------------+-----------------------------------------
&amp;gt;  A new version of Piwik will be out very soon (probably best to wait for
&amp;gt;  the full release, there is a release candidate out today) which fixes
&amp;gt;  critical security issues - upgrading should take no more than 15 mins,
&amp;gt;  would you like your site upgraded?
&amp;gt;
&amp;gt;  &amp;gt; Three security issues have been fixed. We are grateful for security
&amp;gt;  researchers who responsibly disclosed these security issues to us:
&amp;gt;  Abdullah Hussam Gazi (CSRF issue) and Dmitriy Shcherbatov (two XSS
&amp;gt;  issues).
&amp;gt;  &amp;gt;
&amp;gt;  &amp;gt; https://piwik.org/changelog/piwik-2-14-0/
&amp;gt;
&amp;gt; --
&amp;gt; Ticket URL: &amp;lt;https://trac.crin.org/trac/ticket/25&amp;gt;
&amp;gt; CRIN Trac &amp;lt;https://trac.crin.org/trac&amp;gt;
&amp;gt; Trac project for CRIN website and servers.
&amp;gt;
--
Gillian Harrow
Organisational Development Manager
*Child Rights International Network - CRIN*
Unit W125-127, Westminster Business Square
1-45 Durham Street
London SE11 5JH
United Kingdom
E: gillian@crin.org
T: +44 (0)20 7401 2257
Website: www.crin.org
Twitter: @CRINwire
&lt;/pre&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 09 Jul 2015 09:41:00 GMT</pubDate>
      <title>hours, status changed; resolution, totalhours set</title>
      <link>https://trac.crin.org/trac/ticket/25#comment:2</link>
      <guid isPermaLink="false">https://trac.crin.org/trac/ticket/25#comment:2</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0&lt;/em&gt; to &lt;em&gt;0.15&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                set to &lt;em&gt;0.15&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The release version of Piwik 2.14.0 is out, so &lt;a class="ext-link" href="https://stats.crin.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://stats.crin.org/&lt;/a&gt; has been upgraded following  &lt;a class="wiki" href="https://trac.crin.org/trac/wiki/Piwik#Upgrades"&gt;wiki:Piwik#Upgrades&lt;/a&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;sudo -i
cd /var/www
vi piwik/config/config.ini.php
export PIWIK="2.14.0"
wget "https://builds.piwik.org/piwik-$PIWIK.tar.gz"
wget "https://builds.piwik.org/piwik-$PIWIK.tar.gz.asc"
gpg --verify piwik-$PIWIK.tar.gz.asc
cp piwik/config/config.ini.php .
chown -R piwik:piwik /var/www/piwik/
php /var/www/piwik/console core:update
      *** Update ***
      Database Upgrade Required
      Your Piwik database is out-of-date, and must be upgraded before you can continue.
      Piwik database will be upgraded from version 2.13.1 to the new version 2.14.0.
      *** Note: this is a Dry Run ***
      DROP TABLE IF EXISTS `site_setting`;
      CREATE TABLE `site_setting` (
                    idsite INTEGER(10) UNSIGNED NOT NULL AUTO_INCREMENT,
                    `setting_name` VARCHAR(255) NOT NULL,
                    `setting_value` LONGTEXT NOT NULL,
                        PRIMARY KEY(idsite, setting_name)
                      ) ENGINE=InnoDB DEFAULT CHARSET=utf8;
      *** End of Dry Run ***
  A database upgrade is required. Execute update? (y/N) y
  Starting the database upgrade process now. This may take a while, so please be patient.
      *** Update ***
      Database Upgrade Required
      Your Piwik database is out-of-date, and must be upgraded before you can continue.
      Piwik database will be upgraded from version 2.13.1 to the new version 2.14.0.
      The database upgrade process may take a while, so please be patient.
    Executing DROP TABLE IF EXISTS `site_setting`... Done. [1 / 2]
    Executing CREATE TABLE `site_setting` (
                    idsite INTEGER(10) UNSIGNED NOT NULL AUTO_INCREMENT,
                    `setting_name` VARCHAR(255) NOT NULL,
                    `setting_value` LONGTEXT NOT NULL,
                        PRIMARY KEY(idsite, setting_name)
                      ) ENGINE=InnoDB DEFAULT CHARSET=utf8... Done. [2 / 2]
  ****************************************
    Piwik has been successfully updated!
  ****************************************
vi piwik/config/config.ini.php
&lt;/pre&gt;&lt;p&gt;
The &lt;a class="ext-link" href="https://stats.crin.org/index.php?module=Installation&amp;amp;action=systemCheckPage&amp;amp;idSite=1&amp;amp;period=day&amp;amp;date=yesterday"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;System Check&lt;/a&gt; was checked and all looks good.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>