##// END OF EJS Templates
security: limit the maximum password lenght to 72 characters to prevent possible...
security: limit the maximum password lenght to 72 characters to prevent possible server side resource consumption attack. - bcrypt heavy computation can lead to DOS using a very long password .eg 10**8 lenght. - we allowed this on registration or on password update

File last commit:

r1:854a839a default
r2192:a51e727d stable
Show More
release-notes-3.8.2.rst
18 lines | 463 B | text/x-rst | RstLexer

|RCE| 3.8.2 |RNS|

Release Date

  • 2016-03-17

Admin

Admin: Return a forbidden status when trying to create a repository group without sufficient permissions for the parent group.

Security

Security: Update the bundled Git to version 2.7.1 (ᴄᴠᴇ-2016-2324 and ᴄᴠᴇ‑2016‑2315).

Subversion

Subversion: Fix MKCOL requests which are used when committing new folders into a Subversion repository.