This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryFixed an open redirect vulnerability in HttpUtils.
Full changelog
f6d2be99 Release v1.69.1.
e527d4da refactored api token checks to allow short-lived service tokens to access /api/stats
ece0ada1 updated emailer class to fix an issue with the TO: field
e254c034 fixed deprecation warnings
8f55cdbc minor CSS fix
de018c17 fixed config editing and exposure through the API should be limited and disabled if scoold.config_editing_enabled = false
6412441f fixed CORS configuration allowing any origin too broadly
9d61f6fe fixed open redirect issue in HttpUtils
Security Fixes
- Fixed open redirect issue in HttpUtils
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Scoold
Stack Overflow in a JAR. An enterprise-ready Q&A platform with full-text search, SAML, LDAP integration and social login support.
Related context
Related tools
Beta — feedback welcome: [email protected]