提交 34d84fd2 编写于 作者: G GitLab Release Tools Bot

Update CHANGELOG.md for 11.4.2

[ci skip]
上级 cc571e18
...@@ -2,6 +2,17 @@ ...@@ -2,6 +2,17 @@
documentation](doc/development/changelog.md) for instructions on adding your own documentation](doc/development/changelog.md) for instructions on adding your own
entry. entry.
## 11.4.2 (2018-10-25)
### Security (5 changes)
- Escape entity title while autocomplete template rendering to prevent XSS. !2571
- Persist only SHA digest of PersonalAccessToken#token.
- Redact personal tokens in unsubscribe links.
- Block loopback addresses in UrlBlocker.
- Validate Wiki attachments are valid temporary files.
## 11.4.1 (2018-10-23) ## 11.4.1 (2018-10-23)
### Security (2 changes) ### Security (2 changes)
......
---
title: Block loopback addresses in UrlBlocker
merge_request:
author:
type: security
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册