We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 19872
    • 1,078 Posts
    If I am running 2.2.12, does that mean I have to do the full update — as in unpack on server, merge directories, etc. etc.. A full update? Sounds like with earlier versions there is just one file to replace.


      • 18270
      • 68 Posts
      Last time there was a little patch package. Can one be made for this quickly? It sure would be a help for those that need to update a lot of sites quickly.
        • 27708 MODX Staff
        • 2,502 Posts
        Sorry about the confusion in the security announcement (which I'll update) you can follow the same process for 2.2.12 as with 2.2.6-2.2.11 except in this case, you need to replace the following file: https://raw.github.com/modxcms/revolution/v2.2.13-pl/core/model/modx/modx.class.php
          Author of zero books. Formerly of many strange things. Pairs well with meats. Conversations are magical experiences. He's dangerous around code but a markup magician. Blog ✦ Twitter ✦ LinkedIn ✦ GitHub
          • 19872
          • 1,078 Posts
          Ah. Thank you. Much easier than doing a full update.
            • 3749
            • 24,544 Posts
            Jay, I'm assuming that making the change in the MODX class file from this commit will work for any version since 2.2.6, is that correct?

            https://github.com/modxcms/revolution/commit/91f917764a5e2c10cb4079b8513dc90168cfdd25
              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 18270
              • 68 Posts
              Hmm. So there is a different version of the patched file for each version of modx. So I assume we need to grab the specific class file for 2.2.10 pl2 and patch it. Then a different file for 2.2.11 pl2... that is how I was reading it.
              If this is correct I am worried that a lot of people will miss-understand and try to patch all versions with the one class file from 2.2.13 or something. No idea what affect that may have. In which case it would perhaps have been nice to have a patch that would determine your version and patch with the correct version of the class file.

              All that being said, it seems like we simply need to add the following 4 lines at the appropriate location in each of the modx.class.php files in each install. It may be faster to manually go through each installation and patch manually with these new lines.
              if (!$this->context->validate()) {
              $this->log(modX::LOG_LEVEL_ERROR, 'No valid context specified: ' . $contextKey);
              $this->context = null;
              }
              


              e.g. find the _initContext function within core/model/modx/modx.class.php

              protected function _initContext($contextKey, $regenerate = false, $options = null) {
                      $initialized= false;
                      $oldContext = is_object($this->context) ? $this->context->get('key') : '';
                      if (isset($this->contexts[$contextKey]) && $this->contexts[$contextKey] instanceof modContext) {
                          $this->context= & $this->contexts[$contextKey];
                      } else {
                          $this->context= $this->newObject('modContext');
                          $this->context->_fields['key']= $contextKey;
                      }
              ...
              


              and change to

              protected function _initContext($contextKey, $regenerate = false, $options = null) {
                      $initialized= false;
                      $oldContext = is_object($this->context) ? $this->context->get('key') : '';
                      if (isset($this->contexts[$contextKey]) && $this->contexts[$contextKey] instanceof modContext) {
                          $this->context= & $this->contexts[$contextKey];
                      } else {
                          $this->context= $this->newObject('modContext');
                          $this->context->_fields['key']= $contextKey;
              
                          if (!$this->context->validate()) {
                          $this->log(modX::LOG_LEVEL_ERROR, 'No valid context specified: ' . $contextKey);
                          $this->context = null;
                          }
              
                      }
              ...
              

              Can someone please clarify this for us? [ed. note: marcushouse last edited this post 12 years, 6 months ago.]
                • 18270
                • 68 Posts
                Just another note. The oldest version I have siting around here is 2.1.3 and I can see these similar lines.
                protected function _initContext($contextKey) {
                        $initialized= false;
                        $oldContext = is_object($this->context) ? $this->context->get('key') : '';
                        if (isset($this->contexts[$contextKey])) {
                            $this->context= & $this->contexts[$contextKey];
                        } else {
                            $this->context= $this->newObject('modContext');
                            $this->context->_fields['key']= $contextKey;
                        }
                


                If we add the new 4 lines here as shown above that should work shouldn't it? The context->validate() will work on pretty much any revo version I hope?

                Will this method of patching fix every modx Revolution version? Or will some of them differ in some way. [ed. note: marcushouse last edited this post 12 years, 6 months ago.]
                  • 18270
                  • 68 Posts
                  We patched about 120 sites via this method right back to 2.1.3. All sites seemed to run ok after the patch. We need to still do full upgrades to 2.2.13 at some point but should be secure till then. Still awaiting clarification on the above method for versions prior to 2.2.6. Thought it safer to patch them all and see what happens. I'd be happier if I could have the above process confirmed.

                  Thanks.
                    • 22303 MODX Staff
                    • 10,725 Posts
                    Marcus, you are correct in your assumption that you need to patch each version separately, and that it should address the problem for all releases (AFAIK at this time). Because there are almost always changes in every version to the affected file—modx.class.php—you will need to patch the lines you have demonstrated manually to each version. I created the patches as pl2 tags for releases v2.2.6-pl through v2.2.12-pl, so just grab the modx.class.php from the pl2 tag for the release you have installed. I will spend some time this evening and/or tomorrow patching some additional releases for convenience. These tags also contain a modified changelog.txt with a line about the change and release date.

                    Unfortunately we do not have a mechanism to easily patch this one via an extra or a simple download. We have to manually patch each version from the hotfix. It is inconvenient, but not nearly as inconvenient as leaving your site un-patched if or when full disclosure on this vulnerability occurs.

                    We are actively looking for ways to make this process much more convenient for future releases of the product.
                      • 18270
                      • 68 Posts
                      Hi Opengeek,
                      Excellent that is great. Thanks for the clarification.

                      Obviously to determine this I simply checked out the diff on your tagged pl2 versions and noticed it was only the change log and the 4 new lines in modx.class.php. So that is great. Patching manually in this way is not so much an issue as long as we know what lines to add where. In fact it was faster for me that to log into each modx site, download and install a patch. Would be nice to have this information added to the https://forums.modx.com/thread/89486/modx-revolution-2-x-sql-injection#dis-post-492046 page under a sub heading for manual updating (or whatever) for those yet to patch.

                      I treat such vulnerabilities with a lot of caution as when the 2.1.0–2.2.7 vulnerability was announced 9 months back (a different security issue), several of our sites (out of 100 or so) had been hacked literally within the first 48 hours.

                      It is important for people to realize that as soon as a vulnerability is announced, hackers have had it announced to them as well. Most hackers probably already have a huge index of what sites run what systems. It is then just a case for them to figure out how to exploit the vulnerability and execute it on all sites that they have previously indexed as running modx (or any other system for that matter).

                      Thanks again!