diff options
author | GitLab Release Tools Bot <robert+release-tools@gitlab.com> | 2019-01-28 21:19:36 +0000 |
---|---|---|
committer | GitLab Release Tools Bot <robert+release-tools@gitlab.com> | 2019-01-28 21:19:36 +0000 |
commit | 066208f1762b1a60408c62a9098a71b2ed905958 (patch) | |
tree | 41735e7a53cc832a46713c7c29f54fdc14fa6a1a /CHANGELOG.md | |
parent | 3c2ecc9237197d80d75e6cee7d178120ae9f3164 (diff) | |
download | gitlab-ce-066208f1762b1a60408c62a9098a71b2ed905958.tar.gz |
Update CHANGELOG.md for 11.6.6
[ci skip]
Diffstat (limited to 'CHANGELOG.md')
-rw-r--r-- | CHANGELOG.md | 30 |
1 files changed, 30 insertions, 0 deletions
diff --git a/CHANGELOG.md b/CHANGELOG.md index 9939f36ad0d..278a15949ea 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,36 @@ documentation](doc/development/changelog.md) for instructions on adding your own entry. +## 11.6.6 (2019-01-28) + +### Security (24 changes, 1 of them is from the community) + +- Make potentially malicious links more visible in the UI and scrub RTLO chars from links. !2770 +- Don't process MR refs for guests in the notes. !2771 +- Sanitize user full name to clean up any URL to prevent mail clients from auto-linking URLs. !2829 +- Fixed XSS content in KaTex links. +- Disallows unauthorized users from accessing the pipelines section. +- Verify that LFS upload requests are genuine. +- Bump Ruby on Rails to 4.2.11. (@blackst0ne) +- Prevent awarding emojis to notes whose parent is not visible to user. +- Prevent unauthorized replies when discussion is locked or confidential. +- Disable git v2 protocol temporarily. +- Fix showing ci status for guest users when public pipline are not set. +- Fix contributed projects info still visible when user enable private profile. +- Extract GitLab Pages using RubyZip. +- Add more LFS validations to prevent forgery. +- Use common error for unauthenticated users when creating issues. +- Fix slow regex in project reference pattern. +- Fix private user email being visible in push (and tag push) webhooks. +- Fix wiki access rights when external wiki is enabled. +- Group guests are no longer able to see merge requests they don't have access to at group level. +- Fix path disclosure on project import error. +- Restrict project import visibility based on its group. +- Expose CI/CD trigger token only to the trigger owner. +- Notify only users who can access the project on project move. +- Alias GitHub and BitBucket OAuth2 callback URLs. + + ## 11.6.5 (2019-01-17) ### Fixed (5 changes) |