Part of a story covered by 5 sources: “Datasette ships two rounds of security releases: 1.0a39/0.65.4, then 0.65.5/1.0a40 for public/private table permission flaws” — merged summary and timeline →
datasette 0.65.5
AI summary · glm-5.3-flash
Datasette 0.65.5 patches a permission bypass where a trailing newline in a table name could expose private rows (GHSA-h547-rmjf-5m2m).
Datasette 0.65.5 fixes a security issue tracked as GHSA-h547-rmjf-5m2m in which a trailing newline in a requested table name bypassed table permission checks and exposed private rows. The flaw was reported by dpfkdlemtp. The same fix is included in the 1.0a40 alpha release.
- Trailing newline in a table name bypassed table permission checks
- Bypass could expose private rows on affected Datasette instances
- Tracked as GHSA-h547-rmjf-5m2m, reported by dpfkdlemtp
- Fix also carried in the 1.0a40 alpha branch
Full article
Release: datasette 0.65.5 Security fix for an issue where a trailing newline in a requested table name could bypass table permissions and expose private rows, reported by dpfkdlemtp in GHSA-h547-rmjf-5m2m . Tags: security , datasette
This source does not provide full text. Read it at simonwillison.net.