This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
File Storage & Sync
✓ No known CVEs patched
This release patches 1 known CVE
Topics
cloud-alternative
collaboration
collaborative-editing
dropbox
file-server
file-sharing
+12 more
file-storage
file-sync
full-text-search
self-hosted
nextcloud
on-premise
privacy-first
private-cloud
realtime
secure
storage-server
webdav
Affected surfaces
auth
Summary
AI summaryCentralized mitigation of local password timing enumeration attacks (GHSA-29hq-23m2-2j47).
Full changelog
Security
- backend:auth: centralize local password timing mitigation GHSA-29hq-23m2-2j47 (b80efe0)
Thanks to @456789TZ for reporting this. The mitigation against username enumeration via timing attacks has been completed.
Bug Fixes
- auth: require step-up for app password mutations (db19b3e)
- backend:auth: invalidate WebDAV cache on app password deletion (6dae284)
- backend:sync: await usersManager.updateAccesses in 2FA recovery code validation (8f55344)
- docker: add editors section in
environment.yaml(1de3e09) - docker: add Euro-Office config to nginx volumes (a864684)
- frontend:files: add support for dynamic editor naming in OnlyOffice components and error handling (98031da)
Security Fixes
- GHSA-29hq-23m2-2j47 — centralized local password timing mitigation against username enumeration
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About server
Sync-in server · Secure, open-source platform for file storage, sharing, collaboration, and syncing.
Related context
Related tools
Beta — feedback welcome: [email protected]