security: fix CVE 2024 52287 (cherry-pick #12114)#12117
security: fix CVE 2024 52287 (cherry-pick #12114)#12117BeryJu merged 1 commit intoversion-2024.10from
Conversation
* security: CVE-2024-52287 Signed-off-by: Jens Langhammer <jens@goauthentik.io> * add tests Signed-off-by: Jens Langhammer <jens@goauthentik.io> --------- Signed-off-by: Jens Langhammer <jens@goauthentik.io>
✅ Deploy Preview for authentik-docs ready!
To edit notification comments on pull requests, go to your Netlify site configuration. |
Codecov ReportAll modified and coverable lines are covered by tests ✅
✅ All tests successful. No failed tests found. Additional details and impacted files@@ Coverage Diff @@
## version-2024.10 #12117 +/- ##
===================================================
- Coverage 92.66% 92.60% -0.06%
===================================================
Files 761 761
Lines 37863 37891 +28
===================================================
+ Hits 35085 35090 +5
- Misses 2778 2801 +23
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. 🚨 Try these New Features:
|
|
authentik PR Installation instructions Instructions for docker-composeAdd the following block to your AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-a0c00b532fbe5e751a854b674b94d61e3f0aab93
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)sFor arm64, use these values: AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-a0c00b532fbe5e751a854b674b94d61e3f0aab93-arm64
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)sAfterwards, run the upgrade commands from the latest release notes. Instructions for KubernetesAdd the following block to your authentik:
outposts:
container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
image:
repository: ghcr.io/goauthentik/dev-server
tag: gh-a0c00b532fbe5e751a854b674b94d61e3f0aab93For arm64, use these values: authentik:
outposts:
container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
image:
repository: ghcr.io/goauthentik/dev-server
tag: gh-a0c00b532fbe5e751a854b674b94d61e3f0aab93-arm64Afterwards, run the upgrade commands from the latest release notes. |
Cherry-picked security: fix CVE 2024 52287 (#12114)
Signed-off-by: Jens Langhammer jens@goauthentik.io
Signed-off-by: Jens Langhammer jens@goauthentik.io
Signed-off-by: Jens Langhammer jens@goauthentik.io