Ticket #925 (new defect)
Piwik 2.16.3
Reported by: | chris | Owned by: | chris |
---|---|---|---|
Priority: | critical | Milestone: | |
Component: | Unassigned | Keywords: | |
Cc: | sam | Estimated Number of Hours: | 0.0 |
Add Hours to Ticket: | 0 | Billable?: | yes |
Total Hours: | 0.85 |
Description
The Changelog contains:
Security release
This release is rated critical.
The Piwik security engineering team has internally identified a critical security issue and has fixed it in Piwik 2.16.3. We recommend all users to upgrade to this latest version.
Database upgrade
Note: This release contains major database upgrades and upgrading your database will take a long time if you have a lot of data in your database.
Please make sure you read the Update Piwik guide for high traffic instances.
Attachments
Change History
comment:1 Changed 7 weeks ago by chris
- Add Hours to Ticket changed from 0.0 to 0.5
- Total Hours changed from 0.0 to 0.5
comment:2 Changed 7 weeks ago by chris
- Add Hours to Ticket changed from 0.0 to 0.25
- Total Hours changed from 0.5 to 0.75
Request from the Piwik developers:
Can you look in PHP info output, what is your PDO and pdo_mysql versions?
So following the link from the documentation at PenguinServer#APCStatsandPHPinfo we have:
The above has been posted in the forum as requested.
comment:4 follow-up: ↓ 5 Changed 7 weeks ago by sam
Hi Chris Could you stop working on this ticket please. We're now using google analytics so it's now a legacy machine. Would be great to retain access to it for a few days though so I can make sure all the data we need is out of there/ set up on Google. Thanks Sam On 4 October 2016 at 10:24, Transition Technology Trac < trac@tech.transitionnetwork.org> wrote: > #925: Piwik 2.16.3 > ----------------------------------+----------------------------------- > Reporter: chris | Owner: chris > Type: defect | Status: new > Priority: critical | Milestone: > Component: Unassigned | Resolution: > Keywords: | Estimated Number of Hours: 0.0 > Add Hours to Ticket: 0.25 | Billable?: 1 > Total Hours: 0.5 | > ----------------------------------+----------------------------------- > Changes (by chris): > > * hours: 0.0 => 0.25 > * totalhours: 0.5 => 0.75 > > > Comment: > > Request [https://forum.piwik.org/t/array-to-string-conversion- > piwik-2-16-3/21178/4 from the Piwik developers]: > > > Can you look in PHP info output, what is your PDO and pdo_mysql > versions? > > So following the link from the documentation at > PenguinServer#APCStatsandPHPinfo we have: > > [[Image(penguin_phpinfo_pdo.png)]] > > The above has been [https://forum.piwik.org/t/array-to-string-conversion- > piwik-2-16-3/21178/6 posted in the forum] as requested. > > -- > Ticket URL: <https://tech.transitionnetwork.org/trac/ticket/925#comment:2> > Transition Technology <https://tech.transitionnetwork.org/trac> > Support and issues tracking for the Transition Network Web Project. >
comment:5 in reply to: ↑ 4 Changed 7 weeks ago by chris
- Add Hours to Ticket changed from 0.0 to 0.1
- Total Hours changed from 0.75 to 0.85
Replying to sam:
Could you stop working on this ticket please.
OK, but in order to reply to you I have to work on it... but point taken, I won't upgrade the site to the latest version.
We're now using google analytics so it's now a legacy machine.
OK
Would be great to retain access to it for a few days though so I can make
sure all the data we need is out of there/ set up on Google.
How do you not have access to it? Do you need to reset the password? If so there is a link for that at the bottom of the page here:
Changed 7 weeks ago by chris
Changed 7 weeks ago by chris
comment:6 Changed 7 weeks ago by chris
Also note that although you have removed the Piwik webbug from http://transitionnetwork.org/ this server is still collecting data from other sites, Reconomy, the Movie site and archives:
comment:9 Changed 7 weeks ago by sam
Hi Chris, thanks. All I meant is it would be great if you could not delete it from your server until we give you confirmation next week. Thanks Sam On 4 October 2016 at 14:41, Transition Technology Trac < trac@tech.transitionnetwork.org> wrote: > #925: Piwik 2.16.3 > ----------------------------------+----------------------------------- > Reporter: chris | Owner: chris > Type: defect | Status: new > Priority: critical | Milestone: > Component: Unassigned | Resolution: > Keywords: | Estimated Number of Hours: 0.0 > Add Hours to Ticket: 0.1 | Billable?: 1 > Total Hours: 0.75 | > ----------------------------------+----------------------------------- > Changes (by chris): > > * hours: 0.0 => 0.1 > * totalhours: 0.75 => 0.85 > > > Comment: > > Replying to [comment:4 sam]: > > > > Could you stop working on this ticket please. > > OK, but in order to reply to you I have to work on it... but point taken, > I won't upgrade the site to the [https://piwik.org/changelog/ > piwik-2-16-4/ > latest version]. > > > We're now using google analytics so it's now a legacy machine. > > OK > > > Would be great to retain access to it for a few days though so I can > make > > sure all the data we need is out of there/ set up on Google. > > How do you not have access to it? Do you need to reset the password? If so > there is a link for that at the bottom of the page here: > > * https://stats.transitionnetwork.org/ > > -- > Ticket URL: <https://tech.transitionnetwork.org/trac/ticket/925#comment:5> > Transition Technology <https://tech.transitionnetwork.org/trac> > Support and issues tracking for the Transition Network Web Project. >
Following the notes at wiki:PiwikServer#Updates
So I have posted the above to the forum.
The web system check looks OK, but there is this warning: