Blog

openDesk 1.11.2: OpenProject closes security vulnerability

09/01/26 · News
Manuel Krusy
Copied link!

The update to openDesk 1.11.2 includes a fix for a critical security issue in OpenProject.

Projects

The update to OpenProject version 16.6.4 fixes a critical bug in OpenProject's PDF exporter, which allows attackers with upload permissions to access sensitive file information on the server such as configuration files or private project data. For further information see here.

Workaround

If you need a temporary workaround before upgrading, revoke PDF export permissions for users.

Configuration

Additionally, the update to openDesk 1.11.2 increases the standard memory limit for the OpenProject container in the cluster from 3 GB to 4 GB following OpenProject recommendations, fixing a memory issue that caused server errors when accessing OpenProject with only 10-20 users.

Changelog

You can find the full changelog for openDesk 1.11.2 on openCode.

Other articles