github invoicerr-app/invoicerr v2.0.0-alpha.1

pre-release3 hours ago

What's Changed

Security

Three advisories affecting the 1.x line are resolved in this release. All three were reported privately, through the channel SECURITY.md asks for.

  • GHSA-7vg5-q3gv-jx97 (high) — webhook delivery made server-side requests to any URL an administrator could type, with no outbound-URL guard.
  • GHSA-vhjw-gwc5-pjfp (high) — the one-time code standing between a signature link and a legally signed quote could be brute-forced. Reported by @archnexus707
  • GHSA-g76v-ff9h-j6r2 (medium) — a payment method belonging to one company was reachable from another. Reported by @ikkyu3

Thank you. Reporting a flaw privately, and then waiting while a one-person project works through it, is a real cost to the person doing it — and the only reason these were fixed before anyone else found them.

If you run a 1.x instance, none of these are patched there and none will be. Upgrading is the fix.

Full Changelog: v1.4.5a...v2.0.0-alpha.1

Don't miss a new invoicerr release

NewReleases is sending notifications on new releases.