What's Changed
- Issue #531 - Add Security notes to the server documentation by @nttoole in #535
- Issue #557 - Updating readthedocs.yml to use v2 syntax by @EmilyPascua in #558
- issue #531 - Add security note for ait-seq-send by @EmilyPascua in #561
- Create makefile for ease developer set-up by @EmilyPascua in #563
Fixed Vulnerabilities
- Path Traversal in Telemetry CSV Export (GHSA-93gm-4cqq-j774)
- Malicious packet names can no longer write files outside intended directories - Memory Exhaustion via REST API (GHSA-fjr5-6w4j-47xf)
- Blocked file_name_pattern parameter from REST API to prevent attacks
- Can only be set via configuration file - Network Exposure Prevention (GHSA-ccw5-g774-3683)
- ZeroMQ broker now binds to localhost by default instead of all network interfaces
- Use SSH port forwarding for remote access - OpenMCT Plugin Hardening (GHSA-7h55-xp8q-247v)
- Binds to localhost by default
- Prevents cross-site WebSocket attacks with Origin validation
- Fixed crashes from malformed requests
- Added security logging for debug endpoint access
Documentation
- Added security warnings for command sequences with embedded shell commands
- Updated server architecture documentation with security best practices
Full Changelog: 3.1.1...3.1.2