Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Readmeabook 1.2.3: Sicherheitslücke durch JWT-Fallback geschlossen
Version 1.2.3 schließt eine Sicherheitslücke durch einen fest einprogrammierten JWT-Fallback, der gefälschte Administrator-Tokens ermöglichte (betroffen sind Installationen außerhalb des offiziellen Docker-Images wie das Proxmox-VE-Helper-Skript, Docker-Installationen nicht), und behebt zudem das Hängenbleiben von Suche und Download bei 50 Anfragen, das Abschneiden der Suchergebnisse vor Deduplizierung und Ranking, das Löschen falscher Verzeichnisse sowie das dauerhafte Fehlschlagen von Anfragen bei einem durch Rate-Limit blockierten Indexer-Grab.
🎉 Release v1.2.3
Fixes:
✅ Hardcoded JWT fallback enables forged administrator tokens
- https://github.com/kikootwo/ReadMeABook/issues/297
- Installs running outside the official Docker image, including the Proxmox VE helper script, should update now (Proxmox: run
updatein the container). Users on those installs are signed out once. - Docker installs were not affected.
✅ Search / Download stopping at 50
- https://github.com/kikootwo/ReadMeABook/issues/151
- Requests beyond the first 50 are now processed in rotating batches, and RSS matching covers every request awaiting search
✅ Search truncates to 100 results before dedup and ranking, silently dropping the best releases
- https://github.com/kikootwo/ReadMeABook/issues/262
- The full deduplicated result set is now ranked before the 100-result cap is applied
✅ Deleting a request removes a directory rebuilt from the current template, not the one it created
- https://github.com/kikootwo/ReadMeABook/issues/265
- Deletion now uses the path stored when the book was organized
✅ A rate-limited indexer grab marks the request permanently
failedinstead of trying the next release- https://github.com/kikootwo/ReadMeABook/issues/267
- After a 429 or 5xx grab response, the next ranked release is tried automatically
Upgrade:
docker pull ghcr.io/kikootwo/readmeabo docker compose down docker compose up -d ``` …