Security Updates: Apostrophe 3.63.2 released #4448
boutell
announced in
Release Notes
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
A fix for a significant security vulnerability has just been released as Apostrophe 3.63.2. All developers should
npm update
and deploy their Apostrophe 3.x projects to ensure they have this fix. Legacy 2.x projects are unaffected.The fix in question addresses a serious security risk in which arbitrary methods of Apostrophe modules could be called over the network, without arguments, and the results returned to the caller.
While the lack of arguments mitigates the data exfiltration risk, it is possible for the right payload to cause data loss. Therefore this is an urgent upgrade for all Apostrophe 3.x users.
In addition, we addressed two minor security issues:
We’d like to thank the Michelin penetration test red team for the thorough analysis that led to the discovery of these three issues. No other issues were reported by the penetration test team.
Beta Was this translation helpful? Give feedback.
All reactions