- 🔒 Improved validation of fetched urls and responses in v2 oembed endpoint - Kevin Ansfield
See the changelogs for Ghost and Ghost-Admin for the details of every change in this release.
Tag Name: 2.38.1
Release Date: 4/7/2020
GhostOpen-source publishing platform specifically designed for professional bloggers and publications. Focuses on clean, minimalist writing and publishing experience.
This release focuses on security improvements for Ghost's oEmbed functionality across all API versions (v0.1, v2, and canary). The update backports security fixes from Ghost 3.x to ensure consistent validation of fetched URLs and responses in oEmbed endpoints. Additional improvements include standardized request timeouts and user-agent consistency when making external requests.
No migration steps are required for this update. This is a drop-in security improvement that doesn't change any APIs or require configuration changes.
This release contains important security improvements for the oEmbed functionality. All Ghost 2.x users should upgrade to version 2.38.1 as soon as possible to ensure their sites benefit from these security enhancements.
The update is backward compatible and requires no configuration changes or migration steps.
No significant new features were added in this release. This is primarily a security-focused update that backports fixes from Ghost 3.x to the 2.x branch.
Ghost 2.38.1 is a security-focused maintenance release that improves the validation of external content embedded through oEmbed across all API versions. By backporting security fixes from Ghost 3.x, this update ensures consistent and secure handling of embedded content in Ghost 2.x installations.
The changes primarily affect how Ghost validates and processes URLs and responses when embedding external content, with additional improvements to timeout handling and user-agent consistency. These changes enhance security without requiring any configuration changes or breaking existing functionality.
While this update doesn't introduce new features, it significantly improves the security posture of Ghost installations that use embedded content, making it an important update for all Ghost 2.x users.
See the changelogs for Ghost and Ghost-Admin for the details of every change in this release.