Skip to content
GitLab
Menu
Projects
Groups
Snippets
Loading...
Help
Help
Support
Community forum
Keyboard shortcuts
?
Privacy
Imprint
Contact
Login methods
Sign in
Toggle navigation
Menu
Open sidebar
projects.thm.de
GitLab
Commits
466be2f7
Commit
466be2f7
authored
Dec 28, 2018
by
GitLab Release Tools Bot
Browse files
Update CHANGELOG.md for 11.5.6
[ci skip]
parent
f6d8c63b
Changes
19
Hide whitespace changes
Inline
Side-by-side
CHANGELOG.md
View file @
466be2f7
...
...
@@ -2,6 +2,33 @@
documentation
](
doc/development/changelog.md
)
for instructions on adding your own
entry.
## 11.5.6 (2018-12-28)
### Security (17 changes)
-
Escape label and milestone titles to prevent XSS in GFM autocomplete. !2741
-
Validate LFS hrefs before downloading them.
-
Ensure that build token is only used when running.
-
Add subresources removal to member destroy service.
-
Prevent a path traversal attack on global file templates.
-
Allow changing group CI/CD settings only for owners.
-
Authorize before reading job information via API.
-
Prevent leaking protected variables for ambiguous refs.
-
Escape html entities in LabelReferenceFilter when no label found.
-
Prevent private snippets from being embeddable.
-
Issuable no longer is visible to users when project can't be viewed.
-
Don't expose cross project repositories through diffs when creating merge reqeusts.
-
Fix SSRF with import_url and remote mirror url.
-
Fix persistent symlink in project import.
-
Set URL rel attribute for broken URLs.
-
Project guests no longer are able to see refs page.
-
Delete confidential todos for user when downgraded to Guest.
### Other (1 change)
-
Fix due date test. !23845
## 11.5.5 (2018-12-20)
### Security (1 change)
...
...
changelogs/unreleased/54427-label-xss.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Escape html entities in LabelReferenceFilter when no label found
merge_request
:
author
:
type
:
security
changelogs/unreleased/54857-fix-templates-path-traversal.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Prevent a path traversal attack on global file templates
merge_request
:
author
:
type
:
security
changelogs/unreleased/55402-broken-master-karma-test-failing-in-spec-javascripts-boards-components-issue_due_date_spec-js.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Fix due date test
merge_request
:
23845
author
:
type
:
other
changelogs/unreleased/ensure-that-build-token-is-always-running.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Ensure that build token is only used when running
merge_request
:
author
:
type
:
security
changelogs/unreleased/fix-security-group-user-removal.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Add subresources removal to member destroy service
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-11-5-54377-label-milestone-name-xss.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Escape label and milestone titles to prevent XSS in GFM autocomplete
merge_request
:
2741
author
:
type
:
security
changelogs/unreleased/security-11-5-group-cicd-settings-accessible-to-maintainer.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Allow changing group CI/CD settings only for owners.
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-11-5-guests-jobs-api.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Authorize before reading job information via API.
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-11-5-secret-ci-variables-exposed.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Prevent leaking protected variables for ambiguous refs.
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-2754-fix-lfs-import.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Validate LFS hrefs before downloading them
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-48259-private-snippet.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Prevent private snippets from being embeddable
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-53543-user-keeps-access-to-mr-issue-when-removed-from-team.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Issuable no longer is visible to users when project can't be viewed
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-bvl-fix-cross-project-mr-exposure.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Don't expose cross project repositories through diffs when creating merge reqeusts
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-fix-ssrf-import-url-remote-mirror.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Fix SSRF with import_url and remote mirror url
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-import-symlink.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Fix persistent symlink in project import
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-master-url-rel.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Set URL rel attribute for broken URLs.
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-refs-available-to-project-guest.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Project guests no longer are able to see refs page
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-todos_not_redacted_for_guests.yml
deleted
100644 → 0
View file @
f6d8c63b
---
title
:
Delete confidential todos for user when downgraded to Guest
merge_request
:
author
:
type
:
security
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment