]> BookStack Code Mirror - website/blob - content/blog/2024/security-release-v24-10-2.md
Added v24.10.2 post
[website] / content / blog / 2024 / security-release-v24-10-2.md
1 +++
2 categories = ["Releases"]
3 tags = ["Releases"]
4 title = "BookStack Security Release v24.10.2"
5 date = 2024-11-13T12:00:00Z
6 author = "Dan Brown"
7 image = "/images/blog-cover-images/cc-by-sa-4/fence2-dietmar-rabich.jpg"
8 slug = "bookstack-release-v24-10-2"
9 draft = false
10 +++
11
12 BookStack v24.10.2 has been released.
13
14 This is a security release to address a vulnerability in our dependencies where specifically formatted requests could be used to manipulate application configuration in environments where a certain PHP option (register_argc_argv) is enabled. This is not an option that's typically enabled in production web-serving environments, but it's advised to update where uncertain.
15
16 * [Update instructions](https://www.bookstackapp.com/docs/admin/updates)
17 * [GitHub release page](https://github.com/BookStackApp/BookStack/releases/tag/v24.10.2)
18
19 ### Full List of Changes
20
21 * Updated application PHP dependencies.
22 * Updated translations with latest Crowdin changes. ([#5317](https://github.com/BookStackApp/BookStack/pull/5317))
23
24 ### For More Information
25
26 If you have any questions or comments about this advisory:
27 * Open an issue in [the BookStack GitHub repository](https://github.com/BookStackApp/BookStack/issues).
28 * Ask on the [BookStack Discord chat](https://discord.gg/ztkBqR2).
29 * Follow the [BookStack security policy](https://github.com/BookStackApp/BookStack/blob/development/.github/SECURITY.md) to contact someone privately.
30
31 ----
32
33 <span style="font-size: 0.8em;opacity:0.9;">Header Image Credits: <span>Photo by <a href="https://commons.wikimedia.org/wiki/File:D%C3%BClmen,_Kirchspiel,_Wiese_in_der_Bauerschaft_B%C3%B6rnste_--_2016_--_1523-9.jpg">Dietmar Rabich (CC-BY-SA 4.0)</a> - Image Modified</span></span>