Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security problem in Calibre-Web -> Update to 0.6.7 #76

Closed
OzzieIsaacs opened this issue May 5, 2020 · 2 comments
Closed

Security problem in Calibre-Web -> Update to 0.6.7 #76

OzzieIsaacs opened this issue May 5, 2020 · 2 comments

Comments

@OzzieIsaacs
Copy link

linuxserver.io

There was security bug found in Calibre-Web. I created a release with version 0.6.7 to address the issue.
The problem could be avoided in older releases by generating an own session key and providing it to Calibre-Web via environment variable 'SECRET_KEY'

Is tracked under: CVE-2020-12627
Relevant Pull request: janeczku/calibre-web#1337

@project-bot project-bot bot added this to To do in Issue & PR Tracker May 5, 2020
@aptalca
Copy link
Member

aptalca commented May 5, 2020

@CHBMB
Copy link
Member

CHBMB commented May 5, 2020

Built and tested 👍

@CHBMB CHBMB closed this as completed May 5, 2020
Issue & PR Tracker automation moved this from To do to Done May 5, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Development

No branches or pull requests

3 participants