Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. BookStack
  3. Bookstack - Package Updates

Bookstack - Package Updates

Scheduled Pinned Locked Moved BookStack
131 Posts 3 Posters 53.7k Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • girishG Offline
    girishG Offline
    girish
    Staff
    wrote on last edited by
    #42

    [1.14.5]

    • Update BookStack to 21.08.5
    • Release announcement
    • This security release covers a vulnerability which would allow malicious users, who have permission to update or create pages, to load content from files stored within the storage/ or public/ directories (Such as application logs) via the page HTML export system.
    • Added concurrent page editing warnings upon draft save events.
    1 Reply Last reply
    0
    • nebulonN Offline
      nebulonN Offline
      nebulon
      Staff
      wrote on last edited by
      #43

      [1.14.6]

      • Update BookStack to 21.08.6
      • Release announcement
      1 Reply Last reply
      0
      • girishG Offline
        girishG Offline
        girish
        Staff
        wrote on last edited by
        #44

        [1.15.0]

        • Update BookStack to 21.10
        • Release announcement
        • Added Attachment API endpoints. (#2986, #2942)
        • Added Estonian language to BookStack via Crowdin. (#2979)
        • Added support for base64 image content within markdown text via page POST/PUT. (#2898)
        • Updated translations from Crowdin contributors. (#2983)
        • Fixed padding within book-tree sidebar items. Thanks to @ffranchina. (#3000)
        1 Reply Last reply
        0
        • nebulonN Offline
          nebulonN Offline
          nebulon
          Staff
          wrote on last edited by
          #45

          [1.15.1]

          • Update BookStack to 21.10.1
          • Release announcement
          • Fixed image upload vulnerability. Thanks to @Haxatron (#3010)
          • Fixed capitalization for Estonian language option. Thanks to @IndrekHaav. (#3008)
          • Updated PHP packages to prevent abandoned warning. (#3007)
          • Updated translations with latest changes from Crowdin. (#3006)
          1 Reply Last reply
          0
          • nebulonN Offline
            nebulonN Offline
            nebulon
            Staff
            wrote on last edited by
            #46

            [1.15.2]

            • Update BookStack to 21.10.2
            • Release announcement
            • Made further fixes to address image upload vulnerability. Thanks again to @haxatron (#3019)
            • Updated translations with latest changes from Crowdin. (#3014)
            1 Reply Last reply
            0
            • girishG Offline
              girishG Offline
              girish
              Staff
              wrote on last edited by
              #47

              [1.15.3]

              • Update BookStack to 21.10.3
              • Release announcement
              • Fixed path image file path traversal vulnerability. Thanks @theWorstComrade for reporting. (#3030)
              • Prevented HTML attachments being served inline. Thanks @theWorstComrade for reporting. (#3027)
              • Updated translations from latest Crowdin changes. (#3023)
              1 Reply Last reply
              0
              • nebulonN Offline
                nebulonN Offline
                nebulon
                Staff
                wrote on last edited by
                #48

                [1.16.0]

                • Update BookStack to 21.11
                • Release announcement
                1 Reply Last reply
                0
                • girishG Offline
                  girishG Offline
                  girish
                  Staff
                  wrote on last edited by
                  #49

                  [1.16.1]

                  • Update BookStack to 21.11.1
                  • Release announcement
                  • Added custom command support to the logical theme system. (#3072)
                  • Added support for prefers-contrast media setting to increase contrast in faded areas when active. (#2634)
                  • Updated TOTP confirmation view to autofocus on code input. Thanks to @raccettura. (#3068)
                  • Updated translations with latest changes from Crowdin. (#3057)
                  • Updated any links on homepage lists to be more obvious & accessible. (#3046)
                  • Fixed faulty page navigation links when headers are nested within other content. Thanks to @Julesdevops. (#3069, #3058)
                  1 Reply Last reply
                  0
                  • girishG Offline
                    girishG Offline
                    girish
                    Staff
                    wrote on last edited by
                    #50

                    [1.16.2]

                    • Update BookStack to 21.11.2
                    • Release announcement
                    • This is a security release that address a couple of vulnerabilities relating to API access and page draft related content visibility
                    • Fixed issue with greater-than-expected visibility on page-draft-related items. Thanks @Haxatron for reporting. (#3086)
                    • Fixed issue where public API access was not limited by system public control in certain conditions. (#3091)
                    1 Reply Last reply
                    0
                    • girishG Offline
                      girishG Offline
                      girish
                      Staff
                      wrote on last edited by
                      #51

                      [1.16.3]

                      • Update BookStack to 21.11.3
                      • Release announcement
                      • This is a security release that helps prevent potential discovery and harvesting of user details including name and email address.
                      • Helped prevent discovery and harvesting of user information. Thanks @Haxatron for reporting. (#3108)
                      • Updated search API results to include the highlighted preview content. (#3096)
                      • Updated search API results to include item URL. (#3080)
                      1 Reply Last reply
                      0
                      • girishG Offline
                        girishG Offline
                        girish
                        Staff
                        wrote on last edited by
                        #52

                        [1.17.0]

                        • Update BookStack to 21.12
                        • Release announcement
                        • Added webhooks. (#147, #3099)
                        • Added ability to copy books, chapters & roles. (#3118, #1123)
                        • Added audit log IP address search. Thanks to @johnroyer. (#3081)
                        • Updated translations with latest Crowdin changes. (#3117)
                        • Fixed issue where non-ascii content could break search result previews. Thanks to @Kristian-Krastev. (#3113)
                        • Fixed mismatched password validation rules across the application. (#2237)
                        1 Reply Last reply
                        0
                        • nebulonN Offline
                          nebulonN Offline
                          nebulon
                          Staff
                          wrote on last edited by
                          #53

                          [1.17.1]

                          • Update BookStack to 21.12.1
                          • Release announcement
                          • Security Release
                          1 Reply Last reply
                          0
                          • nebulonN Offline
                            nebulonN Offline
                            nebulon
                            Staff
                            wrote on last edited by
                            #54

                            [1.17.2]

                            • Update BookStack to 21.12.2
                            • Release announcement
                            • Improved handling of uploaded images when thumbnails fail to load. (#3142)
                            • Updated translations with latest Crowdin changes. (#3148)
                            • Fixed issue where webhooks would error for specific recycle bin operations. (#3154)
                            • Fixed Spanish invite email subject translation. Thanks to @AitorMatxi. (#3153)
                            • Fixed issue where custom homepage could cause strange deletion behavior and lead to errors. (#3150)
                            1 Reply Last reply
                            0
                            • nebulonN Offline
                              nebulonN Offline
                              nebulon
                              Staff
                              wrote on last edited by
                              #55

                              [1.17.3]

                              • Update BookStack to 21.12.3
                              • Release announcement
                              • Updated user creation flow to not persist the user on invitation sending failure. Thanks to @Julesdevops. (#3179, #3174)
                              • Updated "Recently Updated Pages" view to show update author and date. Thanks to @Julesdevops. (#3177, #3045)
                              • Updated translations with latest Crowdin changes. (#3158)
                              • Updated PDF page export image display to help fix image sizing issues again. (#3120)
                              • Updated "Recently Updated Pages" view to show parent context chain. (#3183)
                              • Fixed potential errors in revision diff view when multi-byte characters are used. (#3170)
                              • Fixed duplicate display in image gallery when uploading multiple images at once. (#3160)
                              • Fixed inaccurate markdown editor cursor position upon sidebar usage. (#3186)
                              1 Reply Last reply
                              0
                              • nebulonN Offline
                                nebulonN Offline
                                nebulon
                                Staff
                                wrote on last edited by
                                #56

                                [1.17.4]

                                • Update BookStack to 21.12.4
                                • Release announcement
                                • Added --external-auth-id option to the bookstack:create-admin command for use with LDAP/SAML2/OIDC instances. (#3222)
                                • Added the ability select preferred language when creating a new user. (#2408, #2576)
                                • Added configuration option for PDF export page size. (#995)
                                • Updated 503 error view to simplify and prevent thrown errors. Thanks to @Julesdevops. (#3210, #3205)
                                • Updated translations with latest Crowdin changes. (#3214)
                                • Fixed mis-represented default registration role and allowed disabling of this option. (#3220, #2338)
                                • Fixed OIDC autodiscovery when keys are provided in a certain format, as provided by Azure. (#3206)
                                1 Reply Last reply
                                0
                                • nebulonN Offline
                                  nebulonN Offline
                                  nebulon
                                  Staff
                                  wrote on last edited by
                                  #57

                                  [1.17.5]

                                  • Update BookStack to 21.12.5
                                  • Release announcement
                                  • Added text for "file" validation messages to provide better responses in Attachment API validation failures. (#3248)
                                  • Fixed WYSIWYG editor code block creation across mulitple lines and block elements. Thanks to @Julesdevops. (#3246, #3200)
                                  • Fixed markdown image data URI extraction failing on large images due to regex match limits. (#3249)
                                  • Updated translations with latest Crowdin changes. (#3225)
                                  1 Reply Last reply
                                  0
                                  • nebulonN Offline
                                    nebulonN Offline
                                    nebulon
                                    Staff
                                    wrote on last edited by
                                    #58

                                    [1.18.0]

                                    • Update BookStack to 22.02
                                    • Release announcement
                                    • Added collapsible content blocks support to the WYSIWYG editor. (#78, #3260)
                                    • Added translation support to the WYSIWYG editor. (#1838)
                                    • Added user management API endpoints. (#3238, #1363, #2701)
                                    • Changed minimum PHP version from 7.3 to 7.4. (#3245, #3152)
                                    • Updated translations with latest Crowdin changes. (#3258, #3251, #3259)
                                    • Updated Korean translations. Thanks to @ististyle. (#3256)
                                    • Updated TinyMCE WYSIWYG editor to the latest version. (#3247)
                                    • Improved PDF export rendering of images within tables. (#3190)
                                    • Fixed potential web console error message when loading the editor. (#2461)
                                    • Fixed issue where OIDC token failures would not be shown to the user. (#3264)
                                    • Fixed issue where the editor could jump-scroll to the top after format change on FireFox (#2692)
                                    1 Reply Last reply
                                    0
                                    • nebulonN Offline
                                      nebulonN Offline
                                      nebulon
                                      Staff
                                      wrote on last edited by
                                      #59

                                      [1.18.1]

                                      • Update BookStack to 22.02.1
                                      • Release announcement
                                      • Updated editor references to avoid caching issue that would prevent WYSIWYG editor from opening. (#3293)
                                      • Updated code blocks within the editor to be more reliable, especially on first insertion. (#3292)
                                      • Updated translations with latest changes from Crowdin. (#3291)
                                      1 Reply Last reply
                                      0
                                      • nebulonN Offline
                                        nebulonN Offline
                                        nebulon
                                        Staff
                                        wrote on last edited by
                                        #60

                                        [1.18.2]

                                        • Update BookStack to 22.02.2
                                        • Release announcement
                                        • Added cache breaker to WYSIWYG onward loading to prevent plugin errors appearing if cached. (#3303)
                                        • Updated translations with latest Crowdin changes. (#3301)
                                        • Updated sidebar fade to be more subtle when in dark mode. (#3203)
                                        • Fixed WYISWYG editor issue where blank lines would collapse. (#3302)
                                        1 Reply Last reply
                                        0
                                        • nebulonN Offline
                                          nebulonN Offline
                                          nebulon
                                          Staff
                                          wrote on last edited by
                                          #61

                                          [1.18.3]

                                          • Update BookStack to 22.02.3
                                          • Release announcement
                                          • Added iframe allow-list control to prevent a range of malicious uses of untrusted iframe sources. (#3314)
                                          • Updated translations with latest Crowdin changes. (#3312)
                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • Bookmarks
                                          • Search