Skip to content

v0.27.3

Latest

Choose a tag to compare

@github-actions github-actions released this 05 Aug 00:33

Security fixes

GHSA-qmr2-wp96-h9ff - API tokens bypass the user's "allowed IP ranges" restriction - #2356

A user's "Allowed IP ranges" list is enforced on interactive logins (password, SSO, OTP) and on tickets, but was never applied to API token authentication over HTTP. An API token belonging to an IP-restricted user was accepted from any source address.

Upgrade if using IP restrictions for users.

Fixes

New Contributors

Full Changelog: v0.27.2...v0.27.3

What's Changed

New Contributors

Full Changelog: v0.27.2...v0.27.3

What's Changed

New Contributors

Full Changelog: v0.27.2...v0.27.3