Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
G
gitlab-ce
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
1
Merge Requests
1
Analytics
Analytics
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Commits
Issue Boards
Open sidebar
nexedi
gitlab-ce
Commits
b011ffe8
Commit
b011ffe8
authored
Nov 09, 2017
by
Michael Kozono
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Add security fixes to CHANGELOG-EE.md
parent
00fc016b
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
8 additions
and
1 deletion
+8
-1
CHANGELOG-EE.md
CHANGELOG-EE.md
+8
-1
No files found.
CHANGELOG-EE.md
View file @
b011ffe8
Please view this file on the master branch, on stable branches it's out of date.
## 10.1.2 (2017-11-08)
-
[SECURITY] Fix vulnerability that could allow any user of a Geo instance to clone any repository on the secondary instance.
-
[SECURITY] Geo JSON web tokens now expire after two minutes to reduce risk of compromise.
-
[SECURITY] Add X-Content-Type-Options header in API responses to make it more difficult to find other vulnerabilities.
-
[SECURITY] Properly translate IP addresses written in decimal, octal, or other formats in SSRF protections in project imports.
-
[FIXED] Fix TRIGGER checks for MySQL.
## 10.1.1 (2017-10-31)
-
No changes.
-
[FIXED] Fix LDAP group sync for nested groups e.g. when base has uppercase or extraneous spaces. !3217
-
[FIXED] Geo: read-only safeguards was not working on Secondary node. !3227
-
[FIXED] fix height of rebase and approve buttons.
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment