This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+1 more
Affected surfaces
Summary
AI summaryUpdates 🛠️ Key Improvements, 🙌 Contributors, and 🚀 Release v1.30.6 across a mixed release.
Full changelog
🚀 Release v1.30.6
📝 Summary
This release resolves a critical Information Disclosure (IDOR) vulnerability within the stats subsystem by enforcing strict Role-Based Access Control (RBAC). It also introduces improved testing coverage for stream deletion edge cases and dependency updates to maintain system integrity.
🛠️ Key Improvements
- 🛡️ Security: Resolved IDOR in stats routing. Viewers with
restrict_camera_accessare now properly scoped and cannot leak global system metrics. - 🚀 Testing: Improved the CI pipeline with environment production dependencies, edge case testing for go2rtc, and CRUD event coverage.
- 🎨 Maintenance: Updated dependencies including a bump to
undicito patch upstream vulnerabilities and refactored internal functions for maintainability.
🙌 Contributors
- @spupuz: Refactoring of stats, notification services, and additional test coverage edge cases.
- @dependabot: Upstream dependency updates.
Security Fixes
- CVE-2024-XXXXX — Information Disclosure (IDOR) in stats routing fixed by enforcing RBAC; viewers with restrict_camera_access now scoped.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About spupuz/VibeNVR
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]