SecureDrop Inbox 1.3.1 released (opens in new tab)
SecureDrop Inbox 1.3.1 is now available.This update addresses a low-priority security issue; we are not aware of any exploitation in the wild. It will be applied automatically during preflight updates, and no further action is required by administrators or journalists. If you have any questions, please or encrypted email.Bypass of securedrop-proxy origin’s limitationA malicious SecureDrop Server could bypass securedrop-proxy’s origin limitation by responding with cross-origin redirects. This ...
Read the original article