From 1c41dd798e028a21b5e8df39ff0f576ab7c98f82 Mon Sep 17 00:00:00 2001 From: Laura Hausmann Date: Wed, 27 Nov 2024 22:08:08 +0100 Subject: [PATCH] Release: v2024.1-beta4.security2 --- CHANGELOG.md | 12 ++++++++++++ Directory.Build.props | 2 +- 2 files changed, 13 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e7fc9e5b..d667c24d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,15 @@ +## v2024.1-beta4.security2 +This is a security hotfix release. It's identical to v2024.1-beta4.security1, except for the security mitigations listed below. Upgrading is strongly recommended for all server operators. + +### Backend +- Several DoS & stack overflow vulnerabilities in the MFM parser were resolved + +### Miscellaneous +- Performance of the MFM parser (and by extension, the frontend) should be significantly improved, as the backport of the security fixes also contains all other performance-related changes since v2024.1-beta4. + +### Attribution +This release was made possible by project contributors: Laura Hausmann + ## v2024.1-beta4.security1 This is a security hotfix release. It's identical to v2024.1-beta4, except for the security mitigations listed below. Upgrading is strongly recommended for all server operators. diff --git a/Directory.Build.props b/Directory.Build.props index 09088b39..1050980b 100644 --- a/Directory.Build.props +++ b/Directory.Build.props @@ -32,7 +32,7 @@ 2024.1 - beta4.security1 + beta4.security2