github girlbossceo/conduwuit v0.3.2

latest releases: v0.4.6, v0.4.6-rc, v0.4.5...
4 months ago

This is a security release.

The Content-Disposition HTTP header has always been set to inline which causes untrusted content opened in browsers to be rendered, including HTML files, instead of downloading. This release forces them to all be attachment. This has no impact on Matrix clients.

Users who use a restrictive Content-Security-Policy are not affected by any XSS concerns here.

Don't miss a new conduwuit release

NewReleases is sending notifications on new releases.