Added v21.11.3 blogpost
This commit is contained in:
parent cd71ab0077
commit 2dcdf2a53a
2 changed files with 44 additions and 0 deletions
41 content/blog/security-release-v21-11-3.md Normal file
41
content/blog/security-release-v21-11-3.md Normal file | @ -0,0 +1,41 @@ | |||
+++ | ||||
categories = ["Releases"] | ||||
tags = ["Releases"] | ||||
title = "BookStack Security Release v21.11.3" | ||||
date = 2021-12-15T13:00:00Z | ||||
author = "Dan Brown" | ||||
image = "/images/blog-cover-images/door-lock-lucas-santos.jpg" | ||||
slug = "bookstack-release-v21-11-3" | ||||
draft = false | ||||
+++ | ||||
| ||||
BookStack v21.11.3 has been released. | ||||
This is a security release that helps prevent potential discovery and harvesting of user | ||||
details including name and email address. | ||||
| ||||
It's advised to upgrade as soon as possible if your BookStack instance is public or | ||||
is used by untrusted members. | ||||
| ||||
* [Update instructions](https://www.bookstackapp.com/docs/admin/updates) | ||||
* [GitHub release page](https://github.com/BookStackApp/BookStack/releases/tag/v21.11.3) | ||||
| ||||
Thanks to @haxatron for discovering and reporting this vulnerability via huntr.dev. | ||||
| ||||
### Full List of Changes | ||||
| ||||
* Helped prevent discovery and harvesting of user information. Thanks @haxatron for reporting. ([#3108](https://github.com/BookStackApp/BookStack/issues/3108)) | ||||
* Updated search API results to include the highlighted preview content. ([#3096](https://github.com/BookStackApp/BookStack/issues/3096)) | ||||
* Updated search API results to include item URL. ([#3080](https://github.com/BookStackApp/BookStack/issues/3080)) | ||||
* Updated translations with latest Crowdin changes. ([#3093](https://github.com/BookStackApp/BookStack/pull/3093)) | ||||
| ||||
| ||||
### For More Information | ||||
| ||||
If you have any questions or comments about this advisory: | ||||
* Open an issue in [the BookStack GitHub repository](BookStackApp/BookStack/issues). | ||||
* Ask on the [BookStack Discord chat](https://discord.gg/ztkBqR2). | ||||
* Follow the [BookStack security policy](https://github.com/BookStackApp/BookStack/blob/master/.github/SECURITY.md) to contact someone privately. | ||||
| ||||
---- | ||||
| ||||
<span style="font-size: 0.8em;opacity:0.9;">Header Image Credits: <span>Photo by <a href="https://unsplash.com/@_staticvoid?utm_source=unsplash&utm_medium=referral&utm_content=creditCopyText">Lucas Santos</a> on <a href="https://unsplash.com/?utm_source=unsplash&utm_medium=referral&utm_content=creditCopyText">Unsplash</a></span></span> |
BIN static/images/blog-cover-images/door-lock-lucas-santos.jpg (Stored with Git LFS) Normal file
BIN
static/images/blog-cover-images/door-lock-lucas-santos.jpg (Stored with Git LFS) Normal file Binary file not shown.
Loading…
Add table
Add a link
Reference in a new issue