Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Jirafeau
  3. Jirafeau - Package Updates

Jirafeau - Package Updates

Scheduled Pinned Locked Moved Jirafeau
22 Posts 4 Posters 6.0k Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • girishG Offline
    girishG Offline
    girish
    Staff
    wrote on last edited by
    #13

    [1.7.0]

    • Update base image to 4.2.0
    1 Reply Last reply
    0
    • Package UpdatesP Online
      Package UpdatesP Online
      Package Updates
      wrote on last edited by
      #14

      [1.8.0]

      • Update Jirafeau to 4.6.0
      • Full changelog
      • New configuration options for allowing to require, check or generate file download passwords
      • Re-implemented server side encryption using PHP's Sodium extension (the formerly used mcrypt extension is deprecated)
      • Keep and show basic download stats
      • Removed Lighttpd's mod_usertrack from Docker config
      • Added <meta name="viewport" to template header to support responsive themes
      1 Reply Last reply
      0
      • Package UpdatesP Online
        Package UpdatesP Online
        Package Updates
        wrote on last edited by
        #15

        [1.8.1]

        • Update Jirafeau to 4.6.1
        • Full Changelog
        • Removed the download button and the corresponding link for encrypted files from the admin interface
        • Fixed an issue with sending the wrong filesize after decrypting an encrypted file
        • Fixed the possibility to bypass the check for CVE-2022-30110 (prevent preview of SVG images) by sending a manipulated HTTP request with a MIME type like "image/svg+XML".
        • We now provide Docker images for AMD64 and ARM64 systems
        • Lots of code refactoring and cleanup
        • Few more little fixes
        • Typo and spelling mistakes
        1 Reply Last reply
        0
        • Package UpdatesP Online
          Package UpdatesP Online
          Package Updates
          wrote on last edited by
          #16

          [1.9.0]

          • symlink custom tos to /app/data/tos.local.txt
          1 Reply Last reply
          0
          • Package UpdatesP Online
            Package UpdatesP Online
            Package Updates
            wrote on last edited by
            #17

            [1.9.1]

            • Update Jirafeau to 4.6.2
            • Full Changelog
            • Allow to configure the language and the availabilities for files for a Docker container (issue #​20)
            • Added an example docker-compose.yaml file for configuring the Docker container
            • Fixed an error occuring on some systems while building the Docker image (issue #​24)
            • Script upload was broken due to a missing return statement (issue #​23)
            • Upgrade from 4.6.1: in-place upgrade
            1 Reply Last reply
            0
            • Package UpdatesP Online
              Package UpdatesP Online
              Package Updates
              wrote on last edited by
              #18

              [1.10.0]

              • Update base image to 5.0.0
              1 Reply Last reply
              0
              • Package UpdatesP Online
                Package UpdatesP Online
                Package Updates
                wrote on last edited by
                #19

                [1.11.0]

                • add checklist
                1 Reply Last reply
                0
                • Package UpdatesP Online
                  Package UpdatesP Online
                  Package Updates
                  wrote on last edited by
                  #20

                  [1.11.1]

                  • Update Jirafeau to 4.6.3
                  • Full Changelog
                  • Fixed the possibility to bypass the checks for CVE-2022-30110 and CVE-2024-12326 (prevent preview of SVG images and other critical files) by sending a manipulated HTTP request with a MIME type like "image/png,text/html". When doing the preview, the MIME type "text/html" takes precedence and you can execute for example JavaScript code.
                  • Compare password hashes using hash_equals()
                  1 Reply Last reply
                  1
                  • Package UpdatesP Online
                    Package UpdatesP Online
                    Package Updates
                    wrote on last edited by
                    #21

                    [1.12.0]

                    • Update Jirafeau to 4.7.0
                    • Full Changelog
                    • Added feature for using shortened download links. This requires a web server that supports URL rewriting, like Apache with mod_rewrite.
                    • Added CSS class tos for addressing the link to the "Terms of Service" page
                    • Download stats introduced in version 4.6.0 were accidentally removed in version 4.6.1. This feature is now available again.
                    • Generated download passwords were not shown after the upload was completed
                    • Uploading a file using script.php with an upload password set always ended up in an "Error 2". This is fixed now.
                    1 Reply Last reply
                    0
                    • Package UpdatesP Online
                      Package UpdatesP Online
                      Package Updates
                      wrote last edited by
                      #22

                      [1.12.1]

                      • Update Jirafeau to 4.7.1
                      • Full Changelog
                      • Fixed another possibility to bypass the checks for CVE-2022-30110, CVE-2024-12326 and CVE-2025-7066 (prevent preview of SVG images and other critical files) by sending a manipulated HTTP request with a MIME type like "image". When doing the preview, the browser tries to automatically detect the MIME type resulting in detecting SVG and possibly executing JavaScript code. To prevent this, MIME sniffing is disabled.
                      • The default value of max_upload_chunk_size_bytes was set to 5000000. Higher values could trigger a bug Chromium-based browsers on servers with HTTP/3 enabled, causing asynchronous uploads to fail.
                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search