Skip to content

1.9.2.post0

Compare
Choose a tag to compare
@github-actions github-actions released this 08 Nov 19:46

Security

  • Fix ORM Leak security vulnerability in Label Studio (CVE-2023-47117). This vulnerability inadvertently made it possible to leak certain secrets from the database via the task filtering endpoint powering Data Manager. We strongly recommend upgrading to this new version, and would like to thank @alex-elttam for identifying this issue in Label Studio.

Breaking changes

  • In general, task filtering expressions that depend on foreign keys will no longer be allowed in this and future versions of Label Studio. However, individual expressions leveraging foreign key relationships (that is, filters containing __, as in updated_by__active_organization) may be allowlisted via the environment variable DATA_MANAGER_FILTER_ALLOWLIST, which accepts a comma-separated list of task filters.

Full Changelog: tags/1.9.2...1.9.2.post0
This changelog was updated in response to a push of f931d9d Workflow run

Jira Release not found
Aha! Release 1.9.2.post0
Release Notes are generated based on git log: No tasks found in Task Tracker.

Turned off Feature Flags (98)

ALL LINES STARTING FROM QUOTE WILL BE IGNORED