Skip to content

Fizzy

vfizzy@1e40457 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 4mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

hotwire kanban rails ruby

Affected surfaces

rce_ssrf

Summary

AI summary

Fixes path traversal vulnerability in ActiveStorage blob key import.

Full changelog

What's Changed

  • Fix path traversal in ActiveStorage blob key import by @flavorjones in https://github.com/basecamp/fizzy/pull/2686

Full Changelog: https://github.com/basecamp/fizzy/compare/[email protected]@1e40457

Security Fixes

  • CVE-2024-12345 — Path traversal in ActiveStorage blob key import

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Fizzy

Get notified when new releases ship.

Sign up free

About Fizzy

Kanban boards for issue and idea tracking

All releases →

Related context

Beta — feedback welcome: [email protected]