Security
We've been running security audits on BBS and are working through what they turn up. This release has the next round of hardening. Updating is recommended for every install.
- Agents can only report on jobs dispatched to them (GHSA-6423-m3jr-236x). A client could mark its own queued jobs, or server-side jobs such as repair and prune, as completed or failed. Thanks to @Lykrin for the report.
- Database dump plugins (agent):
- Extra options for mysqldump, pg_dump and mongodump can't name a file the tool writes or loads (
--result-file,--tab,--plugin-dir,--defaults-file,--file,--out,--archiveand similar). - Database names that start with
-or contain a path separator are refused. - The dump directory must be an absolute path outside system directories.
- The MySQL password is passed in a private option file instead of on the command line, where other local users could read it.
- Extra options for mysqldump, pg_dump and mongodump can't name a file the tool writes or loads (
- Offsite sync:
- Path prefixes can't contain
.or..folders. - Only admins can copy to an SSH host or a storage location.
- Custom S3 endpoints set by non-admins can't point at the server itself.
- Path prefixes can't contain
- Plugin settings: a password or key typed into the edit form is now encrypted when saved. Earlier edits could store it in plain text; the update encrypts any it finds.
- Hosted installs: notification, SMTP, SSO and push relay addresses can't reach internal networks.
- Limits on what clients can send: log lines per job, catalog uploads, and the size of the catalog stream.
- An automated security scan now runs on every change to the code.
Changes you might notice
- Saving a plugin config shows an error for a dump option, dump directory or sync prefix that the rules above refuse. Existing configs that break a rule fail at backup time with the same message.
- On a storage location, a sync path prefix can't start with a number.
Agent updated to 2.98.4.