##// END OF EJS Templates
mercurial: protocol security updates....
mercurial: protocol security updates. - fixes Mercurial CVE for lack of permissions checking on mercurial batch commands - more strict checks for permissions, now default to push instead of pull to be always on safe side. - decypher batch commands and pick top-most permission to be used

File last commit:

r1:854a839a default
r2724:7a057a98 default
Show More
release-notes-2.2.7.rst
13 lines | 256 B | text/x-rst | RstLexer

|RCE| 2.2.7 |RNS|

General

  • 2015-02-03

Fixes

  • Security: fixed severe issue with leaking of auth_tokens(api_keys) on the following API calls; get_repo, update_repo, get_locks, and get_user_groups.