We have released v2.2.3 which contains important security fixes - you need to update as soon as possible if you haven’t done so yet.
Security fixes
- Strip
@
,+
,-
and=
from the beginning of strings when exporting CSV files to avoid security issues when opening the CSV file in Excel - Use 027 instead of 000 umask when temporarily changing it to get the current umask
- Fix LaTeX sanitization to prevent malicious users from running unsafe LaTeX commands through specially crafted abstracts or contribution descriptions, which could lead to the disclosure of local file contents
Improvements
- Improve room booking interface on small-screen devices
- Add user preference for room owners/manager to select if they want to receive notification emails for their rooms
- Show family name field first in user search dialog
- Make date headers clickable in room booking calendar
- Show times in room booking log entries
- Support disabling server-side LaTeX altogether and hide anything that requires it (such as contribution PDF export or the Book of Abstracts). LaTeX is now disabled by default, unless the
XELATEX_PATH
is explicitly set inindico.conf
.
Bugfixes
- Remove 30s timeout from dropzone file uploads
- Fix bug affecting room booking from an event in another timezone
- Fix error when commenting on papers
- Fix performance issue in conferences with public registration count and a high amount of registrations
- Fix confirmation prompt when disabling conference menu customizations
- Fix incorrect days shown as weekend in room booking for some locales
- Fix ACL entries referencing event roles from the old event when cloning an event with event roles in the ACL. Run
indico maint fix-event-role-acls
after updating to fix any affected ACLs - Fix validation issues in coordinates fields when editing rooms
In case you are still on 2.1 and cannot upgrade yet for some reason, we also released v2.1.10 containing just the security fixes.