v2.40.1 #600
Pinned
joseluisq
announced in
Announcements
v2.40.1
#600
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
This new
v2.40.1release brings important security bug fixes for users serving directories with symbolic links (symlinks) as well as other minor improvements.Security vulnerability patch
This particular release patches a Symbolic link path traversal vulnerability (GHSA-459f-x8vq-xjjm)
Any web server that runs with elevated privileges (e.g., root/administrator) and handles user-supplied file uploads is primarily impacted.
We encourage users to update as soon as possible.
Fixes
Refactorings
For more details see the v2.40.1 milestone and the full changelog v2.40.0...v2.40.1.
This discussion was created from the release v2.40.1.
Beta Was this translation helpful? Give feedback.
All reactions