Skip to content

Commit

Permalink
docs(security): update security document
Browse files Browse the repository at this point in the history
  • Loading branch information
LinkinStars committed Feb 22, 2024
1 parent 4f4f8bc commit 7f9b81a
Showing 1 changed file with 20 additions and 0 deletions.
20 changes: 20 additions & 0 deletions community/security.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,26 @@ The Apache Software Foundation takes a rigorous stance on eliminating security i

# Security fixes

## v1.2.1

### CVE-2024-22393

Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content.

https://www.cve.org/CVERecord?id=CVE-2024-22393

### CVE-2024-26578

Repeated submission during registration resulted in the registration of the same user. When users register, if they rapidly submit multiple registrations using scripts, it can result in the creation of multiple user accounts simultaneously with the same name.

https://www.cve.org/CVERecord?id=CVE-2024-26578

### CVE-2024-23349

XSS attack when user enters summary. A logged-in user, when modifying their own submitted question, can input malicious code in the summary to create such an attack.

https://www.cve.org/CVERecord?id=CVE-2024-23349

## v1.2.0

### CVE-2023-49619
Expand Down

0 comments on commit 7f9b81a

Please sign in to comment.