Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Untriaged
updated 2 months ago by @fricklerhandwerk Activity log
  • Created automatic suggestion
  • @fricklerhandwerk deleted maintainer @danieldk maintainer.delete
  • @fricklerhandwerk ignored
    15 packages
    • pkgsRocm.python3Packages.outlines-core
    • typstPackages.outline-summaryst_0_1_0
    • mplus-outline-fonts.githubRelease
    • python314Packages.outlines-core
    • python313Packages.outlines-core
    • python312Packages.outlines-core
    • go-outline
    • pkgsRocm.python3Packages.outlines
    • mplus-outline-fonts.osdnRelease
    • typstPackages.suboutline_0_3_0
    • typstPackages.suboutline_0_2_0
    • typstPackages.suboutline_0_1_0
    • python313Packages.outlines
    • python312Packages.outlines
    • mdbook-pdf-outline
  • @fricklerhandwerk restored package go-outline
  • @fricklerhandwerk ignored
    2 packages
    • go-outline
    • outline
  • @fricklerhandwerk restored package outline
Outline has a suspended user authentication bypass via WebSocket connections

Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket authentication mechanism that allows suspended users to maintain or establish real-time WebSocket connections and continue receiving sensitive operational updates after their account has been suspended. This vulnerability is fixed in 1.1.0.

Affected products

outline
  • ==< 1.1.0

Matching in nixpkgs

pkgs.outline

Fastest wiki and knowledge base for growing teams. Beautiful, feature rich, and markdown compatible

Ignored packages (15)

Package maintainers