update changelog

上级 fbc7bec0
* [CVE-2020-8166] HMAC raw CSRF token before masking it, so it cannot be used to reconstruct a per-form token
* [CVE-2020-8164] Return self when calling #each, #each_pair, and #each_value instead of the raw @parameters hash
## Rails 5.2.4.1 (December 18, 2019) ##
* Fix possible information leak / session hijacking vulnerability.
......
* [CVE-2020-8167] Check that request is same-origin prior to including CSRF token in XHRs
## Rails 5.2.4.1 (December 18, 2019) ##
* No changes.
......
* [CVE-2020-8162] Include Content-Length in signature for ActiveStorage direct upload
## Rails 5.2.4.1 (December 18, 2019) ##
* No changes.
......
* [CVE-2020-8165] Deprecate Marshal.load on raw cache read in RedisCacheStore
* [CVE-2020-8165] Avoid Marshal.load on raw cache value in MemCacheStore
## Rails 5.2.4.1 (December 18, 2019) ##
* No changes.
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册