manyfold3d / manyfold

A self-hosted digital asset manager for 3d print files.
https://manyfold.app
MIT License
742 stars 47 forks source link

Fix security issues from audit #1681

Closed Floppy closed 3 months ago

Floppy commented 10 months ago

Fix issues that came out of #1678. Full report is at https://git.radicallyopensecurity.com/nlnet/ngie-manyfold/-/jobs/127613/artifacts/file/target/report_ngie-manyfold.pdf

High

Elevated

Moderate

Low

NLNet milestone 4.5

Floppy commented 3 months ago

A lovely followup note from our pentester, who can't post it as themselves:

I am the pentester who conducted the security assessment for this project, I'm impressed by the comprehensive list of resolved issues presented here. It's encouraging to see that nearly all identified vulnerabilities appear to have been addressed. While I haven't verified these fixes through retesting, the extensive changes documented and the detailed nature of this update are highly promising. I commend @Floppy 's efforts in prioritizing security and implementing these improvements. Great work on enhancing the project's security posture!

Floppy commented 3 months ago

2242 will be closed as part of the library storage rewrite that is happening imminently as part of #1670