Skip to content

GlobaLeaks

v5.0.94 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Secrets & Credentials
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

accessibility angular anonymity anticorruption bootstrap debian
+13 more
digital-human-rights digital-public-goods dompurify free-software libsodium privacy python security sqlalchemy tor twisted typescript whistleblowing

Affected surfaces

auth rbac deps

Summary

AI summary

Hash password reset, email change, and signup activation tokens at rest close a security vulnerability (CVE-2024-41671).

Full changelog

Changes in version 5.0.94

  • Add support for Ubuntu 26.04 (#4822)
  • Deprecate support for Ubuntu Bionic and Debian Bullseye
  • Implement security enhancements following auditors suggestions:
    -- Hash password reset, email change, and signup activation tokens at rest
    -- Minimize in-memory lifetime of cleartext whistleblower receipt
    -- Avoid local session storage for the user session
    -- Ensure secure_delete is enabled per-connection
    -- Enforce tenant isolation
    -- Use os.path.commonpath in directory_traversal_check to prevent sibling-prefix bypass
    -- Harden globaleaks.service with systemd sandboxing directives
    -- Pin development dependencies and GitHub Actions to commit SHAs
    -- Backport patch for CVE-2024-41671
  • Improve voice recorder anonymization intelligibility and effectiveness:
    -- Fix duplicate audio node connections causing +6dB signal boost
    -- Fix envelope LPF bypassed in the signal chain
    -- Raise envelope LPF cutoff from 20Hz to 60Hz to preserve consonant transients
    -- Use filtered noise carriers above 4kHz for natural fricative reproduction
    -- Replace linear pitch shifting with bilinear frequency warping for stronger anonymization
    -- Add runtime audio format detection (WebM vs MP4) for Safari/iOS compatibility
  • Replace ngx-clipboard with native Clipboard API
  • Revise Accept-Language header parsing
  • Implement notification of report update when a a recipient upload a file (#4816)
  • Fix whistleblower receipt login not opening the report when used from /submission (#4833)
  • Fix failure on sending PGP encrypted support emails
  • Fix daterange rendering broken by leftover placeholder
  • Avoid scrolling on disclaimer when not needed
  • Deprecate usage of Clear-Site-Data header preferring clientside cleaning
  • Bump angular to 21 and other dependencies to their latest stable versions

Breaking Changes

  • Deprecate support for Ubuntu Bionic (18.04) and Debian Bullseye
  • Deprecate usage of Clear-Site-Data header, preferring client‑side cleaning

Security Fixes

  • CVE-2024-41671 — Backport patch and hash password reset, email change, and signup activation tokens at rest; minimize in‑memory cleartext lifetime; avoid local session storage; enable secure_delete per‑connection; enforce tenant isolation; harden globaleaks.service with systemd sandboxing; pin dev dependencies and GitHub Actions

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track GlobaLeaks

Get notified when new releases ship.

Sign up free

About GlobaLeaks

Whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.

All releases →

Beta — feedback welcome: [email protected]