Blog
Latest news about Foswiki
You are here: Blog

Foswiki 2.1.8 is released
this one includes some very important security fixes, update urgent

06 August 2023 | Michael Daum | Release |

FoswikisLatest 28.png

We are very pleased to announce the availability of Foswiki 2.1.8. This release contains 61 fixes relative to 2.1.7, including 9 critical security related fixes.

Upgrading to Foswiki 2.1.8 is highly recommended.

Most notable are:

  • CVE-2023-33756: SpreadSheetPlugin's EVAL feature exposes information about paths and files on the server
  • CVE-2023-24698: Local file inclusion vulnerability in viewfile

But also:

  • directories in working directory are created as world writable 777 permissions
  • possible XSS attack in attachment comments
  • restricted allowed protocols to http and https, i.e. forbid file protocol for local file inclusion
  • prevent symlink attacks by defaulting to a secure location for temporary files
  • update to jquery-ui 1.13.2
  • backport patch to earlier jQuery versons to fix a potential XSS vulnerability
  • possible XSS vulnerability in topic title field

For more details read the release notes

You can download it from different locations immediately, see our download page for details. Please use our task tracker to report any issues. Or contact us on online via IRC or Slack.

For installation information, see the System Requirements and the Installation Guide.

Updating Docker-Foswiki to 2.1.7
Updating a docker instance is easy and fast.

05 April 2022 | Timothy Legge | Release | , , ,

Foswiki-Docker-3.pngtimlegge/docker-foswiki has been updated to Foswiki 2.1.7. What you need to know to upgrade your instance.

FoswikisLatest 8.pngWe are very pleased to announce the availability of Foswiki 2.1.7.

This release addresses significant security issues we discovered in all previous Foswiki releases.

Upgrade to Foswiki 2.1.7 is highly recommended.

This release comes with a total of 110 fixes and enhancements as well as 7 security fixes.

For more details read the release notes

You can download it from different locations immediately, see our download page for details. Please use our task tracker to report any issues. Or contact us on online via IRC or Slack.

For installation information, see the System Requirements and the Installation Guide.

Foswiki, Docker and performance: Examples
An expermental approach using Katacoda

02 February 2021 | Bram van Oosterhout | 1 | , ,

I have spent some time setting up an Apache Foswiki docker container to use as the basis for some course material. I wanted a container that started quickly and worked in the Katacoda course environment. I also wanted it to have good response times , which prompted me to try various "optimisations" that are available in Apache and Foswiki. Since it is easy to set up multiple environments in Katacoda/Docker, my curiosity got the better of me and I decided to compare and contrast. It sent me down a few rabbit holes and I thought the results might be of interest to others. So here is the write up.

pdf-js-bug.jpegWhen opening a PDF file in your browser you most probably are using mozilla's PDF.js component. Recently it started to fail reading large PDF files that are stored on Foswiki and require authentication: files seemed to be corrupt missing the bulk of their data.

The copyright of the content on this website is held by the contributing authors, except where stated elsewhere. See Copyright Statement. Creative Commons License

Legal Imprint    Privacy Policy

This page was cached on 19 Mar 2024 - 00:31.
This website is using cookies. More info. That's Fine