github marcpope/borgbackupserver v2.98.3

2 hours ago

Security

This release comes from a review of the whole codebase. Updating is recommended for every install, especially ones where non-admin users or other people's machines are connected.

  • Text from client machines is escaped in the web interface (GHSA-jwq4-qmhw-54mm). Output a client reports, such as plugin test results, could carry markup that ran in the browser of the person viewing it. Agent-reported text and user-set names are now escaped wherever the page builds HTML. Thanks to @Artur12555 for the report.
  • Access control:
    • A plan can only use its own client's plugin configurations.
    • Repository passphrases show only to users who manage that client's repositories.
    • Retrying a job needs the permission that job needs.
    • Pausing plans over the API needs Manage Plans.
    • Only admins can place repositories on a Remote SSH host.
    • A changed role takes effect at once, and deleted users are signed out.
    • "Require 2FA" also applies to API login.
  • Password reset links use the server's configured address instead of the request's.
  • Email notifications are sent as plain text, and client output can no longer change their format or contents.
  • Stricter checks on data sent by clients (file catalog entries, archive names, log sizes) and on the server's privileged helper, notification URLs and storage paths.
  • Dependencies: league/commonmark 2.10.3, phpseclib 3.0.57.

Changes

  • The client page no longer shows Add Repository or Add Backup Plan to users without permission to finish them (#525).

No agent change; agent stays 2.98.0.

Don't miss a new borgbackupserver release

NewReleases is sending notifications on new releases.