Skip to content

Scoold

v1.69.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

clone cloud-native community-forums forum forum-software forums
+14 more
forumsoftware java knowledge-base knowledgebase q-and-a questions-and-answers scoold self-hosted spring-boot stackexchange stackoverflow stackoverflow-questions support-forum teams

Affected surfaces

auth rbac

Summary

AI summary

Fixed an open redirect vulnerability in HttpUtils.

Full changelog

f6d2be99 Release v1.69.1.
e527d4da refactored api token checks to allow short-lived service tokens to access /api/stats
ece0ada1 updated emailer class to fix an issue with the TO: field
e254c034 fixed deprecation warnings
8f55cdbc minor CSS fix
de018c17 fixed config editing and exposure through the API should be limited and disabled if scoold.config_editing_enabled = false
6412441f fixed CORS configuration allowing any origin too broadly
9d61f6fe fixed open redirect issue in HttpUtils

Security Fixes

  • Fixed open redirect issue in HttpUtils

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Scoold

Get notified when new releases ship.

Sign up free

About Scoold

Stack Overflow in a JAR. An enterprise-ready Q&A platform with full-text search, SAML, LDAP integration and social login support.

All releases →

Related context

Beta — feedback welcome: [email protected]