What's New in this Release
Anchor |
---|
| Blacklist_optn |
---|
| Blacklist_optn |
---|
| Added Blacklist domains optionUsers can now blacklist private networks, hosts or subnets to avoid Server Side Request Forgeries (SSRF) through the Blacklist domains configuration option. By default, this option is disabled. If enabled, users can view a list of sites that are commonly blacklisted. If a request from any of these sites is received after enabling the option, the user is prompted to contact the System Administrator for further processing, or, an error message is displayed.
To view the default list of sites that can be blacklisted, click the link named "listed". A pop-up with the most commonly blacklisted sites appears as shown:
Anchor |
---|
| Enhanced_XSS_security |
---|
| Enhanced_XSS_security |
---|
| Enhanced security against XSS vulnerabilitiesThis app version now has enhanced security implemented to handle any cross-site scripting from the macros. |