Jump to content
  • Released 12/20/2019
  • Current release: No
  • Beta release: No
  • Soft release: No

This is a maintenance release to fix security reports since 4.4.9.


This is a security release and we recommend all clients upgrade as soon as possible.

Security

  • Block binary/octal/hex/decimal based hostnames from being submitted in forms that could trigger an SSRF.
  • Gfycat OEmbed endpoint could create XSS. Also informed Gfycat of issue. - Thanks to René Kroka - https://renekroka.cz for reporting this issue.
  • Addition attachment permission checks when downloading attachments.