Skip to content

v1.4.0

Compare
Choose a tag to compare
@boc-the-git boc-the-git released this 03 Apr 09:09
· 819 commits to mealie-next since this release
f709d11

Highlights

  • Security updates (more on that below)
  • OIDC Login Support - #2860, #3280
  • Initial Startup Workflow - #3204

Security Updates

The team at Github Security Lab provided us with a disclosure containing some recommendations for enhancing the security of Mealie, which have been implemented as part of this release. The vulnerabilities all required an authenticated user to exploit, so were likely only an issue if you allowed open registration to your system.

The key functional change you'll notice is that it's now not possible to scrape recipes/images from URLs that resolve to internal IP addresses. This is to prevent a user being able to map out the network the Mealie instance is part of.

Note that we now default the ALLOW_SIGNUP environment variable to false, previously it was true.

There is a new security page available in the documentation should you want to read up on some extra security steps you can take for your Mealie instance.

The pull request was #3368

What's Changed

New Contributors

Full Changelog: v1.3.2...v1.4.0