Skip to content

Wavelog

v2.4.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 25d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

adif analytics cabrillo clublog eqsl ham-radio
+10 more
hamradio hamradio-application hamradio-logbook logbook logging lotw qrzcom self-hosted web web-based-logger

Summary

AI summary

Critical vulnerability fixed affecting all Wavelog installations from version 1.8 onward.

Full changelog

Important Security Update

This release fixes a critical vulnerability affecting all existing Wavelog installations from version 1.8 onward. While we have no indication of exploitation in the wild, the risk profile changes once the fix is public and we recommend updating to 2.4.2 promptly.
If you cannot update right away, block external access to the /install/ directory at your webserver level as a temporary mitigation.

A full security advisory will be published in approximately 30 days.

Changes

  • Add lightweight search page for qrz.com embedding (by @tallcode)
  • Added User agent for JWKS request in sso implementation (by @HadleySo)
  • Added ability to skip the first login wizard for clubstation members on first login (by @HadleySo)
  • Fixed logout redirect when SSO is enabled (by @HadleySo)
  • fixed a bug, where bandplan saved/adjusted by instanceowner wasn't correctly processed for user (by @int2001)
  • Added automatic DXCC-Lookup at 1st login Wizard (by @int2001)
  • Made the selectable OQRS-Deliverymethods configurable (by @int2001)
  • Fixed a bug for Notes, where titles could be "null" (by @int2001)
  • Added an option to print the OP-Field also on a label (by @int2001)
  • Added SIG/SIG_INFO to LBA-Batchedit (by @int2001)
  • Fixed the duplicate check in the Advanced Logbook. In some cases, it would not show duplicates (by @AndreasK79)
  • Fixed the 13cm band designator in cabrillo export (by @phl0)
  • Made last LoTW upload check a bit more specific (by @phl0)
  • Added links to eqsl.cc and Clublog for callbook search results (by @phl0)
  • Added propagation modes GWAVE and LOS (by @phl0)
  • Fixed some vulnerabilities in the installer (by @HB9HIL, found by BA7LAC)
  • Fixed a bug in CAT URL handling with http and https (by @HB9HIL)

Security Fixes

  • Fixed critical vulnerability affecting all Wavelog installations from version 1.8 onward; temporary mitigation: block external access to /install/ directory.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Wavelog

Get notified when new releases ship.

Sign up free

About Wavelog

Webbased Logging Software for Radio Amateurs. Enhanced QSO logging, statistics and maps for your browser.

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]