diff options
author | Stan Hu <stanhu@gmail.com> | 2016-07-03 09:31:31 +0000 |
---|---|---|
committer | Stan Hu <stanhu@gmail.com> | 2016-07-03 09:31:31 +0000 |
commit | 95336861e97eb72fba8c3034deb2b9b61c9ec961 (patch) | |
tree | cf564f8a637c7e0bd7e81c50a17b01aa783de7f1 /CHANGELOG | |
parent | 328fbd82a36e8c1397e383981ca8ecb789355866 (diff) | |
parent | a034374f004ab2a9e96619438962201b4a6ab222 (diff) | |
download | gitlab-ce-95336861e97eb72fba8c3034deb2b9b61c9ec961.tar.gz |
Merge branch 'redcloth-4-3-2-cve-2012-6684' into 'master'
Update RedCloth to 4.3.2 for CVE-2012-6684
## What does this MR do?
To fix XSS (CVE-2012-6684), upgrade RedCloth to 4.3.2.
## Are there points in the code the reviewer needs to double check?
No.
## Why was this MR needed?
Security vulnerability in RedCloth (CVE-2012-6684) should be fixed to provide GitLab as a secure software.
## What are the relevant issue numbers?
Closes #19169
cf. !2037, !2071
## Does this MR meet the acceptance criteria?
- [x] [CHANGELOG](https://gitlab.com/gitlab-org/gitlab-ce/blob/master/CHANGELOG) entry added
- [n/a] [Documentation created/updated](https://gitlab.com/gitlab-org/gitlab-ce/blob/master/doc/development/doc_styleguide.md)
- [n/a] API support added
- Tests
- [n/a] Added for this feature/bug
- [x] All builds are passing
- [x] Conform by the [style guides](https://gitlab.com/gitlab-org/gitlab-ce/blob/master/CONTRIBUTING.md#style-guides)
- [x] Branch has no merge conflicts with `master` (if you do - rebase it please)
- [x] [Squashed related commits together](https://git-scm.com/book/en/Git-Tools-Rewriting-History#Squashing-Commits)
See merge request !4929
Diffstat (limited to 'CHANGELOG')
-rw-r--r-- | CHANGELOG | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/CHANGELOG b/CHANGELOG index 2f93fcdbaa0..2f29a64df1b 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -38,6 +38,7 @@ v 8.9.5 (unreleased) - Show "locked" label for locked runners on runners admin. !4961 - Fixes issues importing events in Import/Export. Import/Export version bumped to 0.1.1 - Fix import button disabled when import process fail due to the namespace already been taken. + - Security: Update RedCloth to 4.3.2 (Takuya Noguchi) v 8.9.4 - Fix privilege escalation issue with OAuth external users. |