Release Notes

What's new and what's fixed!

Carousel 7.3.8

July 16, 2019
  • CSL-2804 - Carousel API Fetch URL can be exploited to access internal network devices: Improved security by adding an authorization layer to the Carousel API's rendering endpoints.
  • CSL-1684 - Webpage snapshots can pose security risk: Improved security by adding an authorization layer to the Carousel API's rendering endpoints.
  • CSL-2815 - Cloud instances are susceptible to rendering DDOS due to unauthenticated endpoints: The rendering API endpoints now require proper security authentication.