% wget -O pickle.patch <url_to_patch>or: % curl -o pickle.patch <url_to_patch>and then: % patch -p1 < pickle.patch patching file lib/galaxy/util/__init__.py Hunk #1 succeeded at 575 with fuzz 2 (offset -113 lines). patching file lib/galaxy/webapps/galaxy/controllers/ucsc_proxy.pyAgain, for the changes to take effect, YOU MUST RESTART ALL GALAXY SERVER PROCESSES.
The Galaxy Team would like to extend special thanks to Inge Alexander Raknes and colleagues, who privately disclosed the vulnerability, with a full analysis and proof of concept.
Credit for the fix and subsequent testing goes to my fellow Galaxy Team members John Chilton and Dannon Baker.
On behalf of the Galaxy Team,
--nate