This release includes 4 security fixes for security teams reviewing exposed deployments.
Published 1mo
Productivity & Wikis
✓ No known CVEs patched
This release patches 4 known CVEs
Topics
codimd
collaboration
diagrams
editor
hackmd
hedgedoc
+3 more
markdown
notes
real-time
Affected surfaces
auth
rbac
rce_ssrf
Summary
AI summaryUpdates Enhancements, Important notices, and https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-6c2w-8w96-3pcv across a mixed release.
Full changelog
Security fixes
This release contains four security fixes:
- GHSA-6c2w-8w96-3pcv reports a possible HTML injection via the localpart of an email address.
- GHSA-qj78-mjch-wwrv reports a possible Denial-of-Service attack using the YAML frontmatter parsing.
- GHSA-8v9p-5j95-826j reports a possible CSRF attack vector in the GitHub Gist export.
- GHSA-2f9f-w8xq-276v reports a rate-limiting bypass by abusing the CF-Connecting-IP header.
Thanks to Chandler Johnson, taylorodell and alanturing881 for reporting!
Important notices
- When using Cloudflare in front of HedgeDoc, you should set
rateLimitUsingCloudflarein the config.json orCMD_RATE_LIMIT_USING_CLOUDFLAREas environment variable totrue.
Enhancements
- Added a warning page when clicking external links
- Improve the config.json.example file, which is used by
bin/setup - Allow configuration of login / signup rate-limits
- Allow configuration of Cloudflare usage in regards of rate-limits
- Several improvements in the documentation at https://docs.hedgedoc.org
Security Fixes
- GHSA-6c2w-8w96-3pcv — possible HTML injection via email address localpart
- GHSA-qj78-mjch-wwrv — possible Denial-of-Service from YAML frontmatter parsing
- GHSA-8v9p-5j95-826j — possible CSRF attack vector in GitHub Gist export
- GHSA-2f9f-w8xq-276v — rate‑limit bypass abusing CF-Connecting-IP header
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]