Skip to content

spupuz/VibeNVR

v1.30.6 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Media Servers
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ffmpeg lightweight local-storage nvr opensource privacy
+1 more
video-surveillance

Affected surfaces

rbac

Summary

AI summary

Updates 🛠️ Key Improvements, 🙌 Contributors, and 🚀 Release v1.30.6 across a mixed release.

Full changelog

🚀 Release v1.30.6

📝 Summary

This release resolves a critical Information Disclosure (IDOR) vulnerability within the stats subsystem by enforcing strict Role-Based Access Control (RBAC). It also introduces improved testing coverage for stream deletion edge cases and dependency updates to maintain system integrity.

🛠️ Key Improvements

  • 🛡️ Security: Resolved IDOR in stats routing. Viewers with restrict_camera_access are now properly scoped and cannot leak global system metrics.
  • 🚀 Testing: Improved the CI pipeline with environment production dependencies, edge case testing for go2rtc, and CRUD event coverage.
  • 🎨 Maintenance: Updated dependencies including a bump to undici to patch upstream vulnerabilities and refactored internal functions for maintainability.

🙌 Contributors

  • @spupuz: Refactoring of stats, notification services, and additional test coverage edge cases.
  • @dependabot: Upstream dependency updates.

Security Fixes

  • CVE-2024-XXXXX — Information Disclosure (IDOR) in stats routing fixed by enforcing RBAC; viewers with restrict_camera_access now scoped.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track spupuz/VibeNVR

Get notified when new releases ship.

Sign up free

About spupuz/VibeNVR

All releases →

Related context

Earlier breaking changes

  • v1.29.7 Removed the legacy `stream_url` schema from stream routing.
  • v1.28.3 Must update docker-compose.yml with TZ variable for all services

Beta — feedback welcome: [email protected]