rstudio / shiny-server

Host Shiny applications over the web.
https://rstudio.com/shiny/server
Other
712 stars 291 forks source link

Security vulnerabilities in the latest Shiny Server v1.5.20.1002 #561

Closed mahesh2013 closed 5 months ago

mahesh2013 commented 8 months ago

As of today (Nov 14, 2023) there are a number of high and medium security vulnerabilities in the latest Shiny Server v1.5.20.1002 released on December 6, 2022.

Is the new version of the Shiny Server to address these and other vulnerabilities being planned? Any ETA is appreciated.

mahesh2013 commented 8 months ago

@jcheng5 , Any help on these issues or any ETA to fix these issues? thanks

jcheng5 commented 5 months ago

Sorry for not replying earlier, these should've been fixed in Shiny Server 1.5.21, released in December. https://posit.co/download/shiny-server/