This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Secrets & Credentials
✓ No known CVEs patched
This release patches 1 known CVE
Topics
accessibility
angular
anonymity
anticorruption
bootstrap
debian
+13 more
digital-human-rights
digital-public-goods
dompurify
free-software
libsodium
privacy
python
security
sqlalchemy
tor
twisted
typescript
whistleblowing
Affected surfaces
auth
rbac
deps
Summary
AI summaryHash password reset, email change, and signup activation tokens at rest close a security vulnerability (CVE-2024-41671).
Full changelog
Changes in version 5.0.94
- Add support for Ubuntu 26.04 (#4822)
- Deprecate support for Ubuntu Bionic and Debian Bullseye
- Implement security enhancements following auditors suggestions:
-- Hash password reset, email change, and signup activation tokens at rest
-- Minimize in-memory lifetime of cleartext whistleblower receipt
-- Avoid local session storage for the user session
-- Ensure secure_delete is enabled per-connection
-- Enforce tenant isolation
-- Use os.path.commonpath in directory_traversal_check to prevent sibling-prefix bypass
-- Harden globaleaks.service with systemd sandboxing directives
-- Pin development dependencies and GitHub Actions to commit SHAs
-- Backport patch for CVE-2024-41671 - Improve voice recorder anonymization intelligibility and effectiveness:
-- Fix duplicate audio node connections causing +6dB signal boost
-- Fix envelope LPF bypassed in the signal chain
-- Raise envelope LPF cutoff from 20Hz to 60Hz to preserve consonant transients
-- Use filtered noise carriers above 4kHz for natural fricative reproduction
-- Replace linear pitch shifting with bilinear frequency warping for stronger anonymization
-- Add runtime audio format detection (WebM vs MP4) for Safari/iOS compatibility - Replace ngx-clipboard with native Clipboard API
- Revise Accept-Language header parsing
- Implement notification of report update when a a recipient upload a file (#4816)
- Fix whistleblower receipt login not opening the report when used from /submission (#4833)
- Fix failure on sending PGP encrypted support emails
- Fix daterange rendering broken by leftover placeholder
- Avoid scrolling on disclaimer when not needed
- Deprecate usage of Clear-Site-Data header preferring clientside cleaning
- Bump angular to 21 and other dependencies to their latest stable versions
Breaking Changes
- Deprecate support for Ubuntu Bionic (18.04) and Debian Bullseye
- Deprecate usage of Clear-Site-Data header, preferring client‑side cleaning
Security Fixes
- CVE-2024-41671 — Backport patch and hash password reset, email change, and signup activation tokens at rest; minimize in‑memory cleartext lifetime; avoid local session storage; enable secure_delete per‑connection; enforce tenant isolation; harden globaleaks.service with systemd sandboxing; pin dev dependencies and GitHub Actions
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About GlobaLeaks
Whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.
Related context
Beta — feedback welcome: [email protected]