github osm-search/Nominatim v3.4.2
Release 3.4.2

latest releases: v4.4.0, v4.3.2, v4.2.4...
4 years ago

This is a bugfix release which fixes an important security vulnerability in the website code.

The /details endpoint fails to properly sanitize user input and uses it as is in an SQL query. This allows an attacker to inject arbitrary SQL code including querying and updating the database.

All installations still running a 3.4.x release should update to this new version. No changes to the database are necessary. Simply download and build the new version, copy over your settings/local.php file and point your webserver to the new version.

Don't miss a new Nominatim release

NewReleases is sending notifications on new releases.