This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+4 more
Summary
AI summaryAddresses security issue GHSA-8c6x-pfjq-9gr7 with fixes for authentication, mail enumeration, and API validation.
Full changelog
paperless-ngx 2.20.15
[!NOTE]
This release addresses a security issue (GHSA-8c6x-pfjq-9gr7) and is recommended for all users. Our sincere thank you to the community members who reported this.
Bug Fixes
- Fix: use only allauth login/logout endpoints @shamoon (#12639)
- Fix: correctly scope mail account enumeration @shamoon (#12636)
- Fix: prevent intermediate change event when CustomFieldQueryAtom operator changes type @ggouzi (#12597)
- Fix: reject invalid requests to API notes endpoint @ggouzi (#12582)
All App Changes
4 changesSecurity Fixes
- GHSA-8c6x-pfjq-9gr7
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About paperless-ngx
A community-supported supercharged document management system: scan, index and archive all your documents
Beta — feedback welcome: [email protected]