##// END OF EJS Templates
mercurial: protocol security updates....
mercurial: protocol security updates. - fixes Mercurial CVE for lack of permissions checking on mercurial batch commands - more strict checks for permissions, now default to push instead of pull to be always on safe side. - decypher batch commands and pick top-most permission to be used

File last commit:

r1:854a839a default
r2724:7a057a98 default
Show More
release-notes-3.3.2.rst
25 lines | 499 B | text/x-rst | RstLexer
/ docs / release-notes / release-notes-3.3.2.rst
project: added all source files and assets
r1 |RCE| 3.3.2 |RNS|
-----------------
Release Date
^^^^^^^^^^^^
- 2015-06-05
security fixes
^^^^^^^^^^^^^^
* Stored XSS attempts on user login fields, and other text input fields.
* DOM Based XSS attempts
* HTML Injection
* Cross frame scripting (XFS)
* Invalidation of concurrent sessions on password change.
* Downgrading of HTTPS connections.
fixes
^^^^^
* Generation of URLs on system with custom URL prefixes.
* VCSServer: Improved memory management of the cache data used by the server.