Skip to content

v2.5.1

Latest
Compare
Choose a tag to compare
@sedan07 sedan07 released this 27 Aug 16:49
· 10 commits to 2.6 since this release
v2.5.1
d7ecabf

Fixed

  • [SECURITY VULNERABILITY] Configuration leak, user/admin users could leak the value of any config entry from .env file by using variable placeholders. Setting values are now sanitised (GHSA-88f9-7xxh-c688). Thanks to @thomas-chauchefoin-sonarsource
  • [SECURITY VULNERABILITY] New line injection during configuration editing possible by a user/admin. Setting values are now sanitised (GHSA-9jxw-cfrh-jxq6). Thanks to @thomas-chauchefoin-sonarsource
  • [SECURITY VULNERABILITY] Forced reinstall, user/admin users could trick Cachet to allow them to access the /setup endpoint and reinstall the whole instance. Fixed by preventing clearing the instance name. (GHSA-r67m-m8c7-jp83). Thanks to @thomas-chauchefoin-sonarsource
  • Resend edit subscription email to existing subscribers on request #52

Container Image:

sedan07/cachet:v2.5.1