Commit message Age Author Refs
r2201:ef4a80b9
Added tag v4.9.1 for changeset d9aa3b27ac9f
0
r2200:d9aa3b27
release: Finish preparation for 4.9.1
0
r2199:ec0f640e
release: updated pip2nix output for 4.9.1
0
r2198:2a472a97
release: Start preparation for 4.9.1
0
r2197:4edcf89e
docs: added release notes for 4.9.1
0
r2196:2338f289
select2: always escape .text attributes to prevent XSS via vcs references.
0
r2195:af6ecbb0
repo-forks: stable, security, fix issue when forging fork_repo_id could allow reading other people forks.
0
r2194:90609677
auth: don't expose full set of permissions into channelstream payload. This leads to resource discovery security vulnerability
0
r2193:20e24a44
user-groups: fix potential problem with group sync of external plugins. - when using external plugin we used to check for a parameter that set the sync mode. The problem is we only checked if the flag was there. So toggling sync on and off set the value and then left the key still set but with None. This confused the sync and thought the group should be synced !
0
r2192:a51e727d
security: limit the maximum password lenght to 72 characters to prevent possible server side resource consumption attack. - bcrypt heavy computation can lead to DOS using a very long password .eg 10**8 lenght. - we allowed this on registration or on password update
0
< 1 .. 313 314 315 316 317 .. 535 >