This is not the latest release. You can find our latest release, v1.5.10, here.
Version v1.5.8 is a security release containing multiple security fixes, logic fixes, and other optimizations. After the release of v1.5.7, we’ve conducted an internal review and found multiple issues.
Security fixes
- Added more missing routes to the permission system, mainly for managing the advanced project settings, the translations (list, add, modify, delete), and the switch design mode functionality.
- Project creation assistant: Fixed access to the project creation assistant.
- Project members: Fixed access to modify and delete the project members.
- Project groups: Fixed access to create, modify, and delete project groups.
- Setup: Fixed an unprotected setup route.
- Web cron job: The web cron job now rejects empty keys and uses
hash_equalsto verify them. - Submissions: Added a fix to render a link to the form page only if the URL starts with
http://orhttps://. - Import: Changed the token for the import to `random_bytes` to ensure random values.
- Import: Adjusted the logic to ensure that it’s not possible to import something into another project.
- Design mode: Added a CSRF token to the switch design mode functionality.
Other fixes
- Silent mode: Fixed a logic issue that invalidated the results of the honeypot and Proof-of-Work security features.
- API: Changed the parameter retrieval method to ensure the correct data type is returned.
- API: The rule package API pagination was not correctly validated and limited (min, max).
- Rule tester: Removed an unnecessary
rawfilter. - Multiple code style fixes.
Docker
- Added the Dockerfiles to generate mosparo images based on the Alpine base package. Alpine has a much smaller footprint, resulting in a smaller download size and fewer potential security issues. uluzox provided the changes for these new images in #448, #449.
- Converted the scripts to shell scripts and removed unnecessary stuff. Provided by uluzox in #448, #449.
If you’re using the Docker image, we recommend using the Alpine-based images in the future. Switching should be possible without any problems.
Thank you, uluzox, for providing the pull request!
Details of the security issues
Description of the security issue
Most of the important security fixes address improperly protected routes (privilege escalation). As announced in v1.5.7, we’ll switch to a ‘deny-by-default’ system, which will prevent this from happening in the future.
The issue allows the wrong users (in most cases, project members with the editor and reader roles) to access functions that only a project owner should.
The incorrectly protected route in the setup does not allow an attacker to change anything but can generate more load than necessary, making it an important fix. To prevent such issues in the future, we’ve also added another check, so now two different checks protect the setup.
The web cron job endpoint technically allowed empty keys and didn’t use the correct method to validate the keys.
Risk assessment
We recommend updating to v1.5.8 as soon as possible.
Apart from the incorrectly protected setup route, all other fixes are only available if you have project members with the roles editor or viewer, or if you have enabled the web cron job.
If you cannot update as soon as possible, you can block access to the /setup/* routes to prevent the incorrectly protected setup route from causing any harm.
The other security-related fixes are not directly a threat to your mosparo installation.