Skip to content

server

v2.4.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo File Storage & Sync
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

cloud-alternative collaboration collaborative-editing dropbox file-server file-sharing
+12 more
file-storage file-sync full-text-search self-hosted nextcloud on-premise privacy-first private-cloud realtime secure storage-server webdav

Affected surfaces

auth

Summary

AI summary

Centralized mitigation of local password timing enumeration attacks (GHSA-29hq-23m2-2j47).

Full changelog

Security

Thanks to @456789TZ for reporting this. The mitigation against username enumeration via timing attacks has been completed.

Bug Fixes

  • auth: require step-up for app password mutations (db19b3e)
  • backend:auth: invalidate WebDAV cache on app password deletion (6dae284)
  • backend:sync: await usersManager.updateAccesses in 2FA recovery code validation (8f55344)
  • docker: add editors section in environment.yaml (1de3e09)
  • docker: add Euro-Office config to nginx volumes (a864684)
  • frontend:files: add support for dynamic editor naming in OnlyOffice components and error handling (98031da)

Security Fixes

  • GHSA-29hq-23m2-2j47 — centralized local password timing mitigation against username enumeration

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track server

Get notified when new releases ship.

Sign up free

About server

Sync-in server · Secure, open-source platform for file storage, sharing, collaboration, and syncing.

All releases →

Related context

Beta — feedback welcome: [email protected]