Skip to content

v1.0.6

Latest

Choose a tag to compare

@rfxn rfxn released this 05 Apr 19:24
· 5 commits to master since this release

Security Hardening Release

6 security fixes from adversarial pre-ship review + sentinel review:

P2 (release-blocking):

  • _alert_slack_post_message: JSON-escape channel value before awk interpolation — prevents JSON injection from channel names containing " or \

P3 (defense-in-depth):

  • _alert_email_local: CR/LF stripping on all header values (recip, subject, from, reply-to) — prevents header injection if called outside _alert_deliver_email
  • _alert_deliver_email: CR/LF stripping on reply-to, recip, and from in relay path — parity with local MTA path
  • _alert_slack_upload: validate upload URL is HTTPS before uploading file content — rejects http, file, ftp schemes
  • _alert_slack_upload: case-insensitive HTTPS validation — extended case pattern for bash 4.1 compatibility
  • _alert_slack_upload: --data-urlencode for filename parameter — prevents form parameter injection from filenames containing &

Testing:

  • 7 new security regression tests (253 → 260 total)
  • batsman submodule 1.0.3 → 1.4.0

Consumers: BFD and LMD should update their alert_lib submodule/copy to v1.0.6.