2023-03

mailcow/mailcow-dockerized2023-03Mar 3, 2023by DerLinkman

AI Summary

A security update addressing CVE-2023-26490 by replacing XOAUTH2 Perl code with pure Perl code and updating Nextcloud dependencies.

Key Highlights

  • Security fix for CVE-2023-26490 (Imapsync XOAUTH2)
  • OS updates inside containers
  • Nextcloud update to v25.0.4
  • Fix URLHAUS_ABUSE_CH check

New Features

  • Security patch for Imapsync
  • OS container updates
  • Nextcloud patch

Full Release Notes

⚠️ **Security Update!!! This update is fixing  [CVE-2023-26490](https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-3j2f-wf52-cjg7) please patch very soon!!!** 

## What's Changed
* [Imapsync] Use pure perl code for XOAUTH2 authmech ([CVE-2023-26490](https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-3j2f-wf52-cjg7)) by @FreddleSpl0it in https://github.com/mailcow/mailcow-dockerized/commit/04e46f9f5b1e14ba99fe2ec6ca776a69aba9f262
* Update dependency nextcloud/server to v25.0.4 by @renovate in https://github.com/mailcow/mailcow-dockerized/pull/5089
* Translations update from Weblate by @milkmaker in https://github.com/mailcow/mailcow-dockerized/pull/5092
* Add raw attribute for lang.admin.hash_remove_info by @MAGICCC in https://github.com/mailcow/mailcow-dockerized/pull/5098
* Translations update from Weblate by @milkmaker in https://github.com/mailcow/mailcow-dockerized/pull/5102
* fix URLHAUS_ABUSE_CH check by @rekup in https://github.com/mailcow/mailcow-dockerized/pull/5097
* Fix cursor style when hovering 'Aliases' tab by @kritzl in https://github.com/mailcow/mailcow-dockerized/pull/5085
* [Helper] Update expiry-dates.sh by @svengo in https://github.com/mailcow/mailcow-dockerized/pull/5104
* General Update for all container images (OS Updates inside the containers)

## New Contributors
* @rekup made their first contribution in https://github.com/mailcow/mailcow-dockerized/pull/5097
* @kritzl made their first contribution in https://github.com/mailcow/mailcow-dockerized/pull/5085

**Full Changelog**: https://github.com/mailcow/mailcow-dockerized/compare/2023-02a...2023-03
**Security Advisory for  CVE-2023-26490**: https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-3j2f-wf52-cjg7