##// END OF EJS Templates
mercurial: protocol security updates....
mercurial: protocol security updates. - fixes Mercurial CVE for lack of permissions checking on mercurial batch commands - more strict checks for permissions, now default to push instead of pull to be always on safe side. - decypher batch commands and pick top-most permission to be used

File last commit:

r1:854a839a default
r2724:7a057a98 default
Show More
release-notes-3.2.1.rst
18 lines | 260 B | text/x-rst | RstLexer

|RCE| 3.2.1 |RNS|

General

  • 2015-04-20

fixes

  • Security: Fixed a potential XSS vulnerability in user names and user group descriptions.
  • Style: Fixed a form misalignment for the management of user group permissions.