You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
TinyIce 2.9.0
Security:
- CSRF via cached HTTP Basic credentials: a token-free cross-site POST to
/admin/add-user created a superadmin, because isCSRFSafe treated a
request with no session cookie as safe while checkAuth also accepts
Basic and /admin/metadata issues a Basic challenge.
- SSRF past validateOutboundURL: the check only inspected literal IPs in
the configured string, so a hostname resolving into the private network
or a redirect to it went through. Every outbound client now applies the
address policy at connect time, on every hop.
Fixed: AutoDJ edits clearing settings the form never submitted; a
rejected AutoDJ update leaving the mount with no AutoDJ; the Studio's
metadata switch inverting; the volume knob jumping to full at 1%; "load
playlist" loading nothing and remembering it; the mount form's burst size
being discarded; the audit filter hiding 16 of 36 recorded actions;
login ignoring ?next=; disconnected sources staying on screen until
reload; the admin stream event dropping half its fields; explore marking
video mounts as audio-only; the kiosk never showing the station name; a
silent relay upstream parking its goroutine forever; two goroutines
leaked per HLS source flap; MPD lsinfo holding the streamer lock across
os.ReadDir; Opus pause pacing at non-48 kHz; and a data race on
Buffer.Head.
Full notes in CHANGELOG.md.