2024-07
mailcow/mailcow-dockerized2024-07Aug 5, 2024by FreddleSpl0it
AI Summary
Security update fixing CVEs for 2FA bypass and XSS vulnerabilities.
Key Highlights
- CVE-2024-41958: Two-Factor Authentication (2FA) Bypass Vulnerability
- CVE-2024-41959: XSS Vulnerability via API Logs
- CVE-2024-41960: XSS Vulnerability via Relay Hosts Configuration
New Features
- Security patches for DMARC handling
Full Release Notes
⚠️ Vulnerabilities fixed⚠️ --------------------------------- CVE-2024-41958 - Two-Factor Authentication (2FA) Bypass Vulnerability CVE-2024-41959 - XSS Vulnerability via API Logs CVE-2024-41960 - XSS Vulnerability via Relay Hosts Configuration ## What's Changed * Do not add MAILCOW_WHITE on failed DMARC by @dragoangel in https://github.com/mailcow/mailcow-dockerized/pull/5971 * [Postfix] update postscreen_access.cidr by @milkmaker in https://github.com/mailcow/mailcow-dockerized/pull/5974 * Security fixes by @FreddleSpl0it in https://github.com/mailcow/mailcow-dockerized/pull/5976 **Full Changelog**: https://github.com/mailcow/mailcow-dockerized/compare/2024-06c...2024-07