Skip to content

paperless-ngx

v2.20.15 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

angular archiving django dms document-management document-management-system
+4 more
machine-learning ocr optical-character-recognition pdf

Summary

AI summary

Addresses security issue GHSA-8c6x-pfjq-9gr7 with fixes for authentication, mail enumeration, and API validation.

Full changelog

paperless-ngx 2.20.15

[!NOTE]
This release addresses a security issue (GHSA-8c6x-pfjq-9gr7) and is recommended for all users. Our sincere thank you to the community members who reported this.

Bug Fixes

  • Fix: use only allauth login/logout endpoints @shamoon (#12639)
  • Fix: correctly scope mail account enumeration @shamoon (#12636)
  • Fix: prevent intermediate change event when CustomFieldQueryAtom operator changes type @ggouzi (#12597)
  • Fix: reject invalid requests to API notes endpoint @ggouzi (#12582)

All App Changes

4 changes
  • Fix: use only allauth login/logout endpoints @shamoon (#12639)
  • Fix: correctly scope mail account enumeration @shamoon (#12636)
  • Fix: prevent intermediate change event when CustomFieldQueryAtom operator changes type (#12597)
  • Fix: reject invalid requests to API notes endpoint (#12582)

Security Fixes

  • GHSA-8c6x-pfjq-9gr7

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track paperless-ngx

Get notified when new releases ship.

Sign up free

About paperless-ngx

A community-supported supercharged document management system: scan, index and archive all your documents

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]