Security Update 2023-11-21
The original version of the instructions above, combined with a version of grist-core
up until v1.1.7
, produced an insecure configuration which made it possible for an attacker to impersonate any user on the system.
Please be sure to update grist-core and/or the gristlabs/grist
docker image to the latest fixed version (v1.1.8
, stable
, or main
).
This alert also applies to grist-omnibus (docker image gristlabs/grist-omnibus
). Upgrading to the latest version will fix the issue.
The issue affected specifically the suggested configuration of grist-core with traefik. If you used a different configuration, you may not be affected.