This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+3 more
Affected surfaces
Summary
AI summarySecurity hotfix addresses vulnerabilities and missing permission check on the /api/v1/fingerprint endpoint.
Full changelog
Engine versions
- Node:
22.22.3 - Deno:
2.3.1 - MongoDB:
8.0 - Apps-Engine:
1.63.0
Patch Changes
-
Bump @rocket.chat/meteor version.
-
Bump @rocket.chat/meteor version.
-
(#40917 by @dionisio-bot) Escapes HTML tags in exported data
-
(#40891 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#40904 by @dionisio-bot) Fixes missing permission check on the
POST /api/v1/fingerprintendpoint -
(#40938 by @dionisio-bot) Fixes an issue where
descriptionwas incorrectly being used as alternative text for image attachments -
Updated dependencies [01a184640f635866bf4c1c612696acc4eed62311]:
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
Security Fixes
- Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]