Rocket.Chat 8.5.3
Patch release with security fixes including SSRF protection in file downloads, rate limiting for password reset emails, and fixes for special character handling in Omnichannel. Updates Node, Deno, MongoDB, and Apps-Engine engine versions.
Engine versions
- Node:
22.22.3 - Deno:
2.3.1 - MongoDB:
8.0 - Apps-Engine:
1.63.0
Patch Changes
-
Bump @rocket.chat/meteor version.
-
Bump @rocket.chat/meteor version.
-
(#41853 by @dionisio-bot) Adds per-client rate limiting to the unauthenticated sendForgotPasswordEmail method, matching the REST users.forgotPassword endpoint
-
(#41836 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41847 by @dionisio-bot) Replace http with serverFetch in downloadPublicImportFile to add SSRF protection
-
(#41824 by @dionisio-bot) Fixes special characters not being escaped in the visitor name shown in the Omnichannel queue side panel's message preview
-
Updated dependencies []:
- @rocket.chat/core-typings@8.5.3
- @rocket.chat/rest-typings@8.5.3
Source: original entry ↗