v2.32.7 [SECURITY]
·
12 commits
to release/2.32
since this release
Important
Security hardening release.
This patch addresses vulnerabilities responsibly disclosed to Coder by Anthropic's Project Glasswing under their coordinated vulnerability disclosure program.
We strongly recommend upgrading.
See the Security patches section below for the fixed issues and their advisories.
Changelog
BREAKING CHANGES
- fix(coderd)!: restrict OIDC email fallback to first-time account linking (#25712, 670cd427c8) (GHSA-9r87-mvcw-x35f, GHSA-75vm-6w67-gwvp)
- fix!: reject OIDC login when email_verified claim is non-bool or absent (#25713, 0fbee8f9a6) (GHSA-9r87-mvcw-x35f, GHSA-75vm-6w67-gwvp)
- fix!: validate HostnameSuffix and SSHConfigOptions' (#26154, 2dcde52462) (@johnstcn) (GHSA-mcqq-fqgf-rxwm)
- fix!: only trust x-forwarded-host from configured trusted proxies (conflicts) (#26204, a992c2c9d7) (@geokat) (GHSA-5g4w-3vw9-478w)
Security patches
- Clamp template port sharing level in SubAgentAPI (#26061, 5621b756e8) (GHSA-x9qq-2qh5-8rxf)
- Use a random value for a simulated hash for built-in users (#26205, 027cf9af16) (@sreya) (GHSA-8fxq-53rx-ph5f)
- Require update permission to recreate devcontainers (#25812, cc895f6f78) (GHSA-jqj2-x4c5-jfxm)
- Escape agent log HTML (#25808, d3e330c02b) (GHSA-7qw2-f75v-62f7)
- Escape appearance values in HTML output (#25804, 74f08d17e9) (GHSA-h58c-xccx-75m3)
- Server: Verify workspace owner matches app username (#26085, 4c968b6fb9) (@geokat) (GHSA-5wg6-jmq2-53pw)
- Server: Prevent cross-tenant workspace app rebinding (#26103, 8e0a083e56) (@dylanhuff-at-coder) (GHSA-9rjw-3gwp-f59v)
- Agent: Prevent command injection in shell execer (#26235, 94ee8fb4b4) (@zedkipp) (GHSA-359v-rvmf-m3g9)
- Validate agent-supplied AllowedIPs in coordinator (#26144, fa933af8f8) (@f0ssel) (GHSA-wrq8-fcv5-8hvp)
- Prevent session token exfiltration via external app URLs (#26146, 37332e6e7d) (@zedkipp) (GHSA-v54h-cp2w-9x4g)
- Server: Prevent user-admin from resetting owner password (#25709, 931d4fa53b) (GHSA-29xf-69gq-m9jx)
- Reject oversized and invalid zip uploads (#25877, 1f6ccf93e8) (GHSA-2mg2-p7r7-g27f)
- Validate FileSize in NewDataBuilder to prevent OOM DoS (#25710, 2cabbc3f3d) (GHSA-f962-qm93-mj4c)
- Check user user is active in aibridge auth (conflicts) (#26173, 5114fd4ff2) (@pawbana) (GHSA-wqxv-w64v-5wh6)
- Always verify TLS on aibridgeproxyd upstream transport (#26131, 0374b00b63) (@ssncferreira) (GHSA-84rm-42xw-mx52)
Bug fixes
- Rename bundled rstudio.svg to rproject.svg, add real RStudio icon (#26216, eb297f3e1a) (@nickvigilante)
Chores
- Backport release action (#26143, 7ef82012a3)
Compare: v2.32.6...v2.32.7
Container image
docker pull ghcr.io/coder/coder:2.32.7
Install/upgrade
Refer to our docs to install or upgrade Coder, or use a release asset below.