aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMario <mario@mariovavti.com>2022-03-27 19:51:20 +0000
committerMario <mario@mariovavti.com>2022-03-27 19:51:20 +0000
commit680be6cfec51742ace99cd7761e521aaa119cb77 (patch)
tree7656c363ff2c04ad5a10574ca482b16f438bb368
parent03973f5d1d25b54f0b81ccbeb08b18b745b80b22 (diff)
parent2ab3d072b0ed7d9a7adb43bb5a3d56b0d90ec619 (diff)
downloadvolse-hubzilla-680be6cfec51742ace99cd7761e521aaa119cb77.tar.gz
volse-hubzilla-680be6cfec51742ace99cd7761e521aaa119cb77.tar.bz2
volse-hubzilla-680be6cfec51742ace99cd7761e521aaa119cb77.zip
Merge branch 'fix-changelog' into 'dev'
Update changelog with missing fix and cve See merge request hubzilla/core!2018
-rw-r--r--CHANGELOG5
1 files changed, 3 insertions, 2 deletions
diff --git a/CHANGELOG b/CHANGELOG
index f04d0f639..91558b83b 100644
--- a/CHANGELOG
+++ b/CHANGELOG
@@ -28,8 +28,9 @@ Hubzilla 7.2 (2022-??-??)
Bugfixes
- Fix comments_closed date on posts where comments are disabled
- - Fix open redirect via rpath query param
- - Fix local file inclusion in redbasic theme
+ - Fix open redirect via rpath query param (CVE-2022-27256)
+ - Fix cross-site scripting via rpath query param (CVE-2022-27258)
+ - Fix local file inclusion in redbasic theme (CVE-2022-27257)
- Fix baseurl for css and js
- Fix duplicate IDs in login form
- Fix unknown author not fetched if w2w comment arrives