This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+3 more
Affected surfaces
Summary
AI summarySecurity hotfix addressing exported data HTML injection and adding missing permission check to POST /api/v1/fingerprint.
Full changelog
Engine versions
- Node:
22.16.0 - Deno:
1.43.5 - MongoDB:
8.0 - Apps-Engine:
1.60.1
Patch Changes
-
Bump @rocket.chat/meteor version.
-
(#40920 by @dionisio-bot) Escapes HTML tags in exported data
-
(#40895 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#40907 by @dionisio-bot) Fixes missing permission check on the
POST /api/v1/fingerprintendpoint -
Updated dependencies []:
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
Security Fixes
- Security Hotfix – escapes HTML tags in exported data to prevent injection (details: https://docs.rocket.chat/docs/security-fixes-and-updates)
- Adds missing permission check on POST /api/v1/fingerprint endpoint
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]