Skip to content

Releases: mailcow/mailcow-dockerized

๐Ÿฅš๐Ÿ„ Moopril Update 2024 | Security Update

04 Apr 07:36
36b5ccc
Compare
Choose a tag to compare

What's Changed

With the Moopril update, two security vulnerabilities in mailcow will be closed.

  1. CVE-2024-31204: XSS Vulnerability via Exception Handler
  2. CVE-2024-30270: Path Traversal and Arbitrary Code Execution Vulnerability

Thanks to Paul Gerste from Sonar for reporting the security vulnerabilities!

New Contributors

Full Changelog: 2024-02...2024-04

๐Ÿฅ๐Ÿ„ Febmooary 2024 Update | ClamAV Security Update

15 Feb 10:34
8d4ef14
Compare
Choose a tag to compare

What's Changed

Full Changelog: 2024-01e...2024-02
Updated Blog Page here: https://mailcow.email/posts/2024/release-2024-02/

๐Ÿฆพ6๏ธโƒฃ4๏ธโƒฃ ๐Ÿ„ Janmooary 2024 Update Revision E | Corrections for the ARM64 Update

08 Feb 15:19
8ae762a
Compare
Choose a tag to compare

What's Changed

We are aware of the โ€œissueโ€ with SOGo and the error message in the editor. We have already reached out, and once the fix is implemented, we will seamlessly patch the provided SOGo version with the 2024-01e release. This avoids the need for a new subrelease like the current one.

Full Changelog: 2024-01d...2024-01e
Updated Blog Page here: https://mailcow.email/posts/2024/release-2024-01/

Hotfix for 2024-01c: Dovecot Replication Error fix

02 Feb 16:13
c9e9628
Compare
Choose a tag to compare

If you encountered the bug that watchdog is reporting something about Dovecot replication please apply this patch.

If you have problems regarding PHP-FPM and Redis connection issues: #5697 please set the DISABLE_NETFILTER_ISOLATION_RULE to y instead of n inside mailcow.conf and restart the mailcow stack with docker compose down and up -d afterwards

Issue has been fixed in: 57e67ea many, many thanks to @tomudding for quickly finding it!

What's Changed

  • [Dovecot] fix repl-health.sh by @FreddleSpl0it in a310493
  • Updated the Netfilter Image (Original buggy image has been overpatched directly at dockerhub).

Full Changelog: 2024-01c...2024-01d

What's Changed

Full Changelog: 2024-01c...2024-01d

๐Ÿฆพ6๏ธโƒฃ4๏ธโƒฃ ๐Ÿ„ Janmooary 2024 Update Revision C | Netfilter Security Update

02 Feb 14:54
1e09df2
Compare
Choose a tag to compare

โš ๏ธThis update includes a security fix, so we highly recommend that all users upgrade to this latest version to ensure the security of their systems. โš ๏ธ

Users who are unable to update and share their system with potential attackers on the same network, such as with some hosting providers, should apply the following iptables/nftables rule:

iptables:
iptables -I DOCKER-USER ! -i br-mailcow -o br-mailcow -p tcp -m multiport --dport 3306,6379,8983,12345 -j DROP

nftables:
nft insert rule ip "filter" "DOCKER-USER" iifname != "br-mailcow" oifname "br-mailcow" tcp dport {3306, 6379, 8983, 12345} counter packets 0 bytes 0 drop

Read the Security advisory here: GHSA-gmpj-5xcm-xxx6

What's Changed

  • chore(deps): update peter-evans/create-pull-request action to v6 by @renovate in #5683
  • sogo: fix ACL allow authenticated users + rebuild on Bookworm by @DerLinkman in #5688
  • [Postfix] update postscreen_access.cidr by @milkmaker in #5686
  • [Netfilter] add mailcow isolation rule to MAILCOW chain by @FreddleSpl0it in #5696

Full Changelog: 2024-01b...2024-01c
Blog: https://mailcow.email/posts/2024/release-2024-01/

๐Ÿฆพ6๏ธโƒฃ4๏ธโƒฃ ๐Ÿ„ Janmooary 2024 Update | Revision B

22 Jan 10:52
cb97813
Compare
Choose a tag to compare

What's Changed

New Contributors

Full Changelog: 2024-01a...2024-01b
Blog Page: https://mailcow.email/de/posts/2024/release-2024-01/

๐Ÿฆพ6๏ธโƒฃ4๏ธโƒฃ ๐Ÿ„ Janmooary 2024 Update | Revision A

18 Jan 10:56
76f8a5b
Compare
Choose a tag to compare

๐Ÿฆพ6๏ธโƒฃ4๏ธโƒฃ ๐Ÿ„ Janmooary 2024 Update | The Multiarch (x86 + ARM64) & Performance Update

17 Jan 12:53
b5db5dd
Compare
Choose a tag to compare

โš ๏ธ DO A BACKUP BEFORE UPDATING TO BE ON THE SAFE SITE โš ๏ธ

What's Changed

  • Add new SOGoMailHideInlineAttachments option to sogo.conf in #5624
  • [Postfix] update postscreen_access.cidr by @milkmaker in #5625
  • Fixed bg color of form elements in dark mode by @feldsam in #5616
  • [Postfix] Remove pipeling from ehlo keywords as we block it in data by @dragoangel in #5621
  • [Rspamd] add option to skip domain wide footer on reply e-mails by @FreddleSpl0it in #5612
  • Update Dockerfiles to Alpine 3.19 by @MAGICCC in #5592
  • [Web] use template for default values in mbox and domain creation by @FreddleSpl0it in #5615
  • chore(deps): update dependency composer/composer to v2.6.6 by @renovate in #5581
  • chore(deps): update dependency tianon/gosu to v1.17 by @renovate in #5550
  • chore(deps): update dependency phpredis/phpredis to v6.0.2 by @renovate in #5549
  • chore(deps): update dependency krakjoe/apcu to v5.1.23 by @renovate in #5522
  • unbound: rewrote of healthcheck by @DerLinkman in #5639
  • mailcow Multiarch (x86 and ARM64) support by @DerLinkman in #5587
  • Implemented Server Side processing for domains and mailboxes datatables by @feldsam in #5523

Full Changelog: 2023-12a...2024-01
Blog Post: https://mailcow.email/posts/2024/release-2024-01

๐Ÿ›ท ๐Ÿ„ Moocember 2023 Update Revision A | Postfix CVE-2023-51764 Security Update

29 Dec 19:40
cb0b023
Compare
Choose a tag to compare

What's Changed

  • chore(deps): update dependency nextcloud/server to v28.0.1 by @renovate in #5614
  • Translations update from Weblate by @milkmaker in #5617
  • [Postfix] Do not remove X-Mailer header by @feldsam in #5504
  • Translations update from Weblate by @milkmaker in #5622
  • [Postfix] set smtpd_forbid_bare_newline = yes

Full Changelog: 2023-12...2023-12a

๐Ÿ›ท ๐Ÿ„ Moocember 2023 Update | Netfilter NFTables Support and Banlist Endpoint

19 Dec 10:53
121f012
Compare
Choose a tag to compare

What's Changed

New Contributors

Full Changelog: 2023-11a...2023-12