This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+1 more
Affected surfaces
Summary
AI summaryUpdates π οΈ Key Improvements, π Release v1.31.0, and π Contributors across a mixed release.
Full changelog
π Release v1.31.0
π Summary
This minor release introduces native Single Sign-On (SSO / OAuth 2.0) integration into VibeNVR, bringing enterprise-grade identity management to your deployments. Alongside these major authentication features, we have patched a critical security vulnerability affecting webhook transmissions.
π οΈ Key Improvements
- π Authentication (SSO & OIDC): Introduced full support for OAuth 2.0 and OpenID Connect. You can now link your VibeNVR local accounts to external Identity Providers (such as Authentik, Keycloak, or Google Workspace) using a strict Zero-Trust subject mapping.
- β¨ SSO Auto-Redirect & RP-Logout: Added the ability to enable Auto-Redirect, which seamlessly bypasses the local login screen to immediately prompt your IdP. We also introduced RP-Initiated Logout, ensuring that logging out of VibeNVR securely terminates your session at the provider level.
- π‘οΈ Security (Webhooks): Fixed a HIGH severity Server-Side Request Forgery (SSRF) bypass in webhook transmissions. The engine now explicitly blocks malicious redirects to internal IP addresses (e.g., Cloud Metadata).
π Contributors
- @spupuz: π‘οΈ Fixed the critical SSRF vulnerability in webhooks (PR #230) and championed the new SSO architecture.
Security Fixes
- CVE-2024-XXXXX β Fixed highβseverity ServerβSide Request Forgery (SSRF) bypass in webhook transmissions, now blocks redirects to internal IP addresses such as cloud metadata services
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About spupuz/VibeNVR
All releases βRelated context
Related tools
Beta — feedback welcome: [email protected]