CTFd 3.8.8 has been released with security fixes for 4 vulnerabilities, including one a critical vulnerability.
- Reset password emails are now always sent to emails associated with user accounts
- An attacker with knowledge of an admin's email address could coerce CTFd to send a forgot password email for that admin to an email address they control and gain access to the admin account.
- We recommend admins rotate their password and review the IPs in their CTFd instance as well as any relevant server logs. Hosted CTFd customers can contact us with any questions or concerns.
- Admins can no longer arbitrarily write files to the filesystem when using certain S3 implementations for file uploads
- Hosted CTFd was not affected by this vulnerability
- Tokens from banned users are no longer accepted
- Unlocks can no longer be created against inaccessible challenges
We recommend all CTFd users update their instance to v3.8.8.
v3.8.8 has already been deployed to Hosted CTFd customers.
Self-hosted users can download the latest version of CTFd from Github or by downloading the latest version of the Enterprise installer from their account at https://cloud.ctfd.io/.