CSteipp has uploaded a new change for review.

  https://gerrit.wikimedia.org/r/107321


Change subject: Update Release Notes
......................................................................

Update Release Notes

Change-Id: Icc4757e167bce1c466ba3f39be65b5d2eba4482b
---
M RELEASE-NOTES-1.22
1 file changed, 5 insertions(+), 0 deletions(-)


  git pull ssh://gerrit.wikimedia.org:29418/mediawiki/core 
refs/changes/21/107321/1

diff --git a/RELEASE-NOTES-1.22 b/RELEASE-NOTES-1.22
index d3d74bc..ff858e91 100644
--- a/RELEASE-NOTES-1.22
+++ b/RELEASE-NOTES-1.22
@@ -9,6 +9,11 @@
 
 === Changes since 1.22.0 ===
 
+* (bug 57550) SECURITY: Disallow stylesheets in SVG Uploads
+* (bug 58088) SECURITY: Don't normalize U+FF3C to \ in CSS Checks
+* (bug 58472) SECURITY: Disallow -o-link in styles
+* (bug 58553) SECURITY: Return error on invalid XML for SVG Uploads
+* (bug 58699) SECURITY: Fix RevDel log entry information leaks
 * (bug 58178) Restore compatibility with curl < 7.16.2.
 * (bug 56931) Updated the plural rules to CLDR 24. They are in new format
   which is detailed in UTS 35 Rev 33. The PHP parser and evaluator as well as

-- 
To view, visit https://gerrit.wikimedia.org/r/107321
To unsubscribe, visit https://gerrit.wikimedia.org/r/settings

Gerrit-MessageType: newchange
Gerrit-Change-Id: Icc4757e167bce1c466ba3f39be65b5d2eba4482b
Gerrit-PatchSet: 1
Gerrit-Project: mediawiki/core
Gerrit-Branch: REL1_22
Gerrit-Owner: CSteipp <cste...@wikimedia.org>

_______________________________________________
MediaWiki-commits mailing list
MediaWiki-commits@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/mediawiki-commits

Reply via email to