Impact
This vulnerability could have allowed an attacker to hijack some of our subdomains under readthedocs.com/readthedocs.org. This was due to our existing protections disallowing subdomains of app.readthedocs.org/com only.
Users of https://readthedocs.org/ and https://readthedocs.com/ do not need to take any further action, we have taken measures to ensure that the security issue is now fully fixed. This issue was discovered by a member of our team, and we have seen no signs that this vulnerability was abused in the wild.
Custom installations
We don't officially support custom installations of Read the Docs, but If you are using a custom installation, we recommend you to upgrade. If your domain includes a country code TLD, like domain.co.uk, you'll need to override the RTD_RESTRICTED_DOMAINS setting, otherwise the application will block all custom domains that end with co.uk.
Patches
This vulnerability has been patched with our 15.5.1 release.
References
For more information
If you have any questions or comments about this advisory, email us at [email protected] (PGP)
Impact
This vulnerability could have allowed an attacker to hijack some of our subdomains under
readthedocs.com/readthedocs.org. This was due to our existing protections disallowing subdomains ofapp.readthedocs.org/comonly.Users of https://readthedocs.org/ and https://readthedocs.com/ do not need to take any further action, we have taken measures to ensure that the security issue is now fully fixed. This issue was discovered by a member of our team, and we have seen no signs that this vulnerability was abused in the wild.
Custom installations
We don't officially support custom installations of Read the Docs, but If you are using a custom installation, we recommend you to upgrade. If your domain includes a country code TLD, like
domain.co.uk, you'll need to override theRTD_RESTRICTED_DOMAINSsetting, otherwise the application will block all custom domains that end withco.uk.Patches
This vulnerability has been patched with our 15.5.1 release.
References
For more information
If you have any questions or comments about this advisory, email us at [email protected] (PGP)