Skip to content

zipline

v4.6.4 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 20d File Storage & Sync
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

docker file-server file-sharing file-upload file-uploader gallery
+7 more
mantine reactjs screenshot sharex sharex-server sharex-uploader zipline

Affected surfaces

auth

Summary

AI summary

Security fixes including GHSA-fp8p-hf8g-fw65, GHSA-jh6v-w5f3-8p4x, and GHSA-2qgq-hv52-jhqq.

Full changelog

⚠️ Please update to v4.6.4 as soon as possible as it contains many security fixes. It is highly recommended to update Zipline, patch releases do not contain breaking changes and only usually contain bug fixes. If you do happen to encounter any bugs after updating, please create a detailed issue explaining it. ⚠️

What's Changed

  • 🚨 GHSA-fp8p-hf8g-fw65, GHSA-jh6v-w5f3-8p4x, GHSA-2qgq-hv52-jhqq
  • fixed OAuth flow to use nonce validation
  • fixed folder ownership checks
  • fixed rate limits on logins being too aggressive
  • fixed dynamic imports
  • added content security policy for raw file routes
  • removed fluent-ffmpeg in favor of built-in stuff
  • updated packages

Full Changelog: https://github.com/diced/zipline/compare/v4.6.3...v4.6.4

Security Fixes

  • GHSA-fp8p-hf8g-fw65
  • GHSA-jh6v-w5f3-8p4x
  • GHSA-2qgq-hv52-jhqq

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track zipline

Get notified when new releases ship.

Sign up free

About zipline

A ShareX/file upload server that is easy to use, packed with features, and with an easy setup!

All releases →

Related context

Beta — feedback welcome: [email protected]