This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+3 more
Affected surfaces
Summary
AI summarySecurity hotfix and missing permission check on the POST /api/v1/fingerprint endpoint
Full changelog
Engine versions
- Node:
22.22.2 - Deno:
2.3.1 - MongoDB:
8.0 - Apps-Engine:
1.62.0
Patch Changes
-
Bump @rocket.chat/meteor version.
-
Bump @rocket.chat/meteor version.
-
(#40918 by @dionisio-bot) Escapes HTML tags in exported data
-
(#40892 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#40905 by @dionisio-bot) Fixes missing permission check on the
POST /api/v1/fingerprintendpoint -
(#40939 by @dionisio-bot) Fixes an issue where
descriptionwas incorrectly being used as alternative text for image attachments -
Updated dependencies [42461654757b3b5b9fa454bf4867542170b48126]:
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
Security Fixes
- Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]