Skip to content
This repository was archived by the owner on May 2, 2024. It is now read-only.

v1.1.2: URGENT SECURITY PATCH

Choose a tag to compare

@reesericci reesericci released this 25 Oct 20:24
· 1 commit to main since this release

This release contains an urgent security patch for email OTP login.

On previous versions, any actor could log into any account with email OTP enabled by entering any number into the OTP field after requesting an email.

We thank zinc for reporting this issue.

Administrators: update your version of Obl.ong immediately.

Lastly, email OTPs now only get sent if the code has expired, or you manually hit resend - cutting down on SMTP costs.