This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 2mo
Alerting & Incidents
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
alerta
api-server
mongodb
monitoring
postgresql
Summary
AI summaryFeature-rich release adding alert counters, CAS authentication, LDAP improvements, SMTP SSL skip option, and environment pagination. Multiple security bugfixes including SQL injection prevention and self-update endpoint restriction.
Security Fixes
- Restrict self-update endpoint to allowlisted fields
- Parameterize Postgres query parser for SQL injection prevention
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]