⬆️ Update BookStackApp/BookStack to v25.12.9#434
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the
Comment |
|
This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation. |
6baa6e8 to
9b4efc9
Compare
9b4efc9 to
2bf9fcd
Compare
2bf9fcd to
55fc31d
Compare
55fc31d to
9c52347
Compare
9c52347 to
3f90c08
Compare
3f90c08 to
0f39258
Compare
This PR contains the following updates:
v25.12.2→v25.12.9Release Notes
BookStackApp/BookStack (BookStackApp/BookStack)
v25.12.9: BookStack v25.12.9Compare Source
Security Release
BookStack v25.12.9 has been released.
This is a security release to address a vulnerability where style code in page content could be used to manipulate the page beyond the expected content area in some revision views, opening up risk of potential phishing and/or tracking by bad page editors.
We advise that you update your instance if you allow untrusted users to create or edit pages.
Thanks to Alex Dan (@windbreaker555 on GitHub) for their responsible discovery and reporting of this issue.
Full List of Changes
v25.12.8: BookStack v25.12.8Compare Source
Links
Full List of Changes
This release contains the following fixes and changes:
v25.12.7: BookStack v25.12.7Compare Source
This release specifically addresses a scenario, introduced in v25.12.4, where loading the editor of a page, last updated/created by a different user with blank content, would result in an error.
Links
Full List of Changes
This release contains the following fixes and changes:
v25.12.6: BookStack v25.12.6Compare Source
This release specifically addresses issues introduced in v25.12.4, where drawings could become non-editable in certain scenarios due to content filtering rules.
Links
Full List of Changes
This release contains the following fixes and changes:
v25.12.5: BookStack v25.12.5Compare Source
This release specifically addresses folder permission issues (often showing as an error when attempting to access content) which could occur from changes introduced in v25.12.4.
Links
Full List of Changes
This release contains the following fixes and changes:
v25.12.4: BookStack v25.12.4Compare Source
Security Release
BookStack v25.12.4 has been released.
This is a security release to address a vulnerability where style code in page content could be used to manipulate the page beyond the expected content area, opening up risk of potential phishing and/or tracking by bad page editors.
We advise that you update your instance if you allow untrusted users to create or edit pages.
Thanks to SeongYun Moon (@Moonster8282 on GitHub) for their responsible discovery and reporting of this issue.
Additional Update Notices
ALLOW_CONTENT_SCRIPTSenv option is now considered deprecated. It's advised to use theAPP_CONTENT_FILTERINGoption, as documented here, instead if needed.If you experience issues with your page content being over-filtered feel free to raise an issue on GitHub where we can check if the behaviour is intentional or something which needs to be patched.
You can use the new page content filtering option, with a value of
jhfwhich should match the prior version filtering, but this will remove a layer of content filtering security so is not recommend.Full List of Changes
v25.12.3: BookStack v25.12.3Compare Source
Security Release
BookStack v25.12.3 has been released.
This is a security release to address a vulnerability where form elements in page content could be used to trick more privileged users into making API requests.
We strongly advise that you update your instance if you allow untrusted users to create or edit pages.
Thanks to Joud Zakharia of zentrust partners GmbH for the discovery of this vulnerability, and thanks to Sven Faßbender of zentrust partners GmbH for their responsible disclosure and great communication of this issue.
Additional Update Notices
Full List of Changes
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.