Skip to content

v5.4.1

Compare
Choose a tag to compare
@Bubka Bubka released this 17 Nov 22:53
· 26 commits to master since this release

Security release

  • Fix XSS & SSRF vulnerabilities (thx to the XBOW team).
  • Content Security Policy is now available and enable by default. CSP helps to prevent or minimize the risk of certain types of security threats.
    If CSP is already enable on your server, you can set the CONTENT_SECURITY_POLICY environment variable to false to disable it at 2FAuth level.