github Chocobozzz/PeerTube v8.1.6

latest release: v8.2.0-rc.2
7 hours ago

IMPORTANT NOTES

  • Follow v8.1.0 IMPORTANT NOTES if you upgrade from PeerTube <= v8.0.2

SECURITY

  • Fix SQL injection coming from actor inbox URL when updating actor follow scores. Thanks to Nagarajan Selvaraj Paulmony for reporting this vulnerability 🙏
  • Reject JSON-LD objects with special properties. Thanks to Mastodon security team for reporting this vulnerability 🙏
  • Restricts role assignment to administrators only
  • Prevent external auth token replay
  • Prevent SSRF on import and channel sync
  • Stricter rate limit to ask password reset

Don't miss a new PeerTube release

NewReleases is sending notifications on new releases.