This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+6 more
Summary
AI summaryUpdates Security fixes, Other changes, and Part-DB 2.12.3 across a mixed release.
Full changelog
[!IMPORTANT]
This version contains security fixes, it is recommended to update to this version immediately.
[!IMPORTANT]
If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8
Part-DB 2.12.3
Security fixes
- Fixed missing SVG sanitatization, when file was uploaded with non-svg extension
- Added CSP headers to static files, to prevent script execution, should an vulnerable file be uploaded somehow
Other changes
- Updated KiCad symbols
- Updated dependencies
Full Changelog: https://github.com/Part-DB/Part-DB-server/compare/v2.12.2...v2.12.3
Security Fixes
- Fixed missing SVG sanitatization for uploads with non‑SVG extensions
- Added CSP headers to static files to prevent script execution from uploaded content
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]