]> BookStack Code Mirror - website/blob - content/blog/2024/security-release-v23-12-3.md
Added v23.12.3 security release post
[website] / content / blog / 2024 / security-release-v23-12-3.md
1 +++
2 categories = ["Releases"]
3 tags = ["Releases"]
4 title = "BookStack Security Release v23.12.3"
5 date = 2024-02-26T12:00:00Z
6 author = "Dan Brown"
7 image = "/images/blog-cover-images/unsplash/fence-duong-chung.jpg"
8 slug = "bookstack-release-v23-12-3"
9 draft = false
10 +++
11
12 BookStack v23.12.3 has been released.
13 This is a security release that addresses a vulnerability in PDF generation
14 that could be exploited to perform blind server-side-request forgery.
15
16 Upgrade is advised where untrusted users have permission to create/edit/update page
17 content in your instance.
18
19 * [Update instructions](https://www.bookstackapp.com/docs/admin/updates)
20 * [GitHub release page](https://github.com/BookStackApp/BookStack/releases/tag/v23.12.3)
21
22 ### Full List of Changes
23
24 * Updated PHP dependencies, primarily to update php-svg-lib package.
25
26 ### For More Information
27
28 If you have any questions or comments about this advisory:
29 * Open an issue in [the BookStack GitHub repository](https://github.com/BookStackApp/BookStack/issues).
30 * Ask on the [BookStack Discord chat](https://discord.gg/ztkBqR2).
31 * Follow the [BookStack security policy](https://github.com/BookStackApp/BookStack/blob/development/.github/SECURITY.md) to contact someone privately.
32
33 ----
34
35 <span style="font-size: 0.8em;opacity:0.9;">Header Image Credits: <span>Photo by <a href="https://unsplash.com/@chungharu?utm_content=creditCopyText&utm_medium=referral&utm_source=unsplash">duong chung</a> on <a href="https://unsplash.com/photos/selective-focus-photography-of-wooden-fence-3QDe3kGZjXY?utm_content=creditCopyText&utm_medium=referral&utm_source=unsplash">Unsplash</a></span></span>