8000 Security Overview · BookStackApp/BookStack · GitHub
[go: up one dir, main page]

Skip to content

Security: BookStackApp/BookStack

Security

.github/SECURITY.md

Security Policy

Supported Versions

Only the latest version of BookStack is supported. We generally don't support older versions of BookStack due to maintenance effort and since we aim to provide a fairly stable upgrade path for new versions.

Security Notifications

If you'd like to be notified of new potential security concerns you can sign-up to the BookStack security mailing list.

Reporting a Vulnerability

If you've found an issue that likely has no impact to existing users (For example, in a development-only branch) feel free to raise it via a standard GitHub bug report issue.

If the issue could have a security impact to BookStack instances, please directly contact the lead maintainer @ssddanbrown. You will need to log in to be able to see the email address on the GitHub profile page. Alternatively you can send a DM via Mastodon to @danb@fosstodon.org.

Please be patient while the vulnerability is being reviewed. Deploying the fix to address the vulnerability can often take a little time due to the amount of preparation required, to ensure the vulnerability has been covered, and to create the content required to adequately notify the user-base.

Thank you for keeping BookStack instances safe!

  • Server Side Request Forgery Through Content Exports
    GHSA-8wfc-w2r5-x7cr published Dec 6, 2020 by ssddanbrown
    Moderate
  • Cross-Site Scripting Through Link Attachments
    GHSA-7p2j-4h6p-cq3h published Oct 31, 2020 by ssddanbrown
    Low
  • Cross-Site Scripting and Redirects Through Page Content
    GHSA-r2cf-8778-3jgp published Oct 31, 2020 by ssddanbrown
    Moderate
  • Low
  • Cross-Site Scripting Through Comment Creation
    GHSA-5vf7-q87h-pg6w published May 2, 2020 by ssddanbrown
    Moderate
  • Remote Code Execution Through Image Uploads
    GHSA-g9rq-x4fj-f5hx published Mar 8, 2020 by ssddanbrown
    High
  • Learn more about advisories related to BookStackApp/BookStack in the GitHub Advisory Database
    0