++++
+categories = ["Releases"]
+tags = ["Releases"]
+title = "BookStack Security Release v24.05.4"
+date = 2024-08-29T15:00:00Z
+author = "Dan Brown"
+image = "/images/blog-cover-images/cc-by-sa-4/fence-dietmar-rabich.jpg"
+slug = "bookstack-release-v24-05-4"
+draft = false
++++
+
+BookStack v24.05.4 has been released.
+
+This is a security release to address issues found in LDAP group syncing, where in certain scenarios a user could be matched to extra roles incorrectly,
+and an issue with content visibility in "book-show" API responses would not have permissions applied properly.
+
+Upgrade is strongly advised for instances where LDAP authentication is used with group syncing, or where
+the REST API is used to fetch contents of books ("books-read" endpoint).
+
+Thanks to Linus Nagel and their team at WorkSimple GmbH for reporting this API vulnerability.
+
+* [Update instructions](https://www.bookstackapp.com/docs/admin/updates)
+* [GitHub release page](https://github.com/BookStackApp/BookStack/releases/tag/v24.05.4)
+
+### Full List of Changes
+
+* Updated API docs with consistent parameter types. ([#5183](https://github.com/BookStackApp/BookStack/issues/5183))
+* Updated default content iframe embed max-width to align with other content types. ([#5130](https://github.com/BookStackApp/BookStack/issues/5130))
+* Updated LDAP group sync to query via full DN.
+* Updated translations with latest Crowdin changes. ([#5118](https://github.com/BookStackApp/BookStack/pull/5118))
+* Fixed books read API response not applying visibility control to chapter contents.
+* Fixed API docs users response showing extra property. ([#5178](https://github.com/BookStackApp/BookStack/issues/5178))
+* Fixed database error thrown when using out dev docker setup. ([#5124](https://github.com/BookStackApp/BookStack/issues/5124))
+* Fixed RTL display issues with tasklist checkboxes. ([#5134](https://github.com/BookStackApp/BookStack/issues/5134))
+
+### For More Information
+
+If you have any questions or comments about this advisory:
+* Open an issue in [the BookStack GitHub repository](https://github.com/BookStackApp/BookStack/issues).
+* Ask on the [BookStack Discord chat](https://discord.gg/ztkBqR2).
+* Follow the [BookStack security policy](https://github.com/BookStackApp/BookStack/blob/development/.github/SECURITY.md) to contact someone privately.
+
+----
+
+<span style="font-size: 0.8em;opacity:0.9;">Header Image Credits: <span>Photo by <a href="https://commons.wikimedia.org/wiki/File:D%C3%BClmen,_Nonnenwall,_Zaun_--_2020_--_4007.jpg">Dietmar Rabich (CC-BY-SA 4.0)</a> - Image Modified</span></span>
\ No newline at end of file