🔒 New Kitten & JSDB Releases

Security fix, JSDB 6.0.1.

This is a critical update.

• JSDB¹ versions 6.0.0 and below suffer from potential data corruption/arbitrary code execution as string keys were not being sanitised in the same way string values were² (so this is relevant to you if you’re storing untrusted data as keys in your data structures in JSDB and/or Kitten databases without carrying out any of your own sanitisation at the application level).

• The latest Kitten release uses JSDB version 6.0.1. Your deployment servers will automatically update in the next few hours. On your development machines, please run `kitten update` in your terminal or use the Update feature in Kitten Settings from your browser.

• If you are using Kitten’s Database App Modules³ feature in your apps, you will have installed JSDB manually and you should update your installation to version 6.0.1.

¹ https://codeberg.org/small-tech/jsdb/
² https://codeberg.org/small-tech/jsdb/issues/22
³ https://kitten.small-web.org/reference/#database-app-modules

#Kitten #SmallWeb #JSDB #JavaScriptDatabase #KittenRelease #JSDBRelease #securityUpdate #criticalUpdate

jsdb

A zero-dependency, transparent, in-memory, streaming write-on-update JavaScript database for the Small Web that persists to a JavaScript transaction log.

Codeberg.org
Cisco discloses a 10.0 CVSS rating vulnerability in SSM On-Prem

Cisco has revealed a significant security flaw in its Smart Software Manager On-Prem (SSM On-Prem), scoring a perfect 10.0 on the Common Vulnerability

Stack Diary
Oracle releases 386 new security updates for the July patch round

Oracle has issued a stern warning about critical vulnerabilities across many of its products, emphasizing the urgency for organizations to install the

Stack Diary
Mastodon: Security flaw allows unauthorized access to posts

Mastodon, the decentralized social network, is urging instance operators to update their server software immediately due to a high-risk security

Stack Diary