[Rt-commit] rt annotated tag, rt-4.2.14rc2, created. rt-4.2.14rc2

Shawn Moore shawn at bestpractical.com
Thu Jun 15 14:55:48 EDT 2017


The annotated tag, rt-4.2.14rc2 has been created
        at  19da8163e11622d860d8dce996f27f6ef21d1346 (tag)
   tagging  74e13acf775e116d6af21809fe9c999aa8ece263 (commit)
  replaces  rt-4.2.14rc1
 tagged by  Shawn M Moore
        on  Thu Jun 15 14:34:40 2017 -0400

- Log -----------------------------------------------------------------
Version 4.2.14rc2
-----BEGIN PGP SIGNATURE-----

iQIcBAABAgAGBQJZQtNAAAoJEDdW4lQxRAUgL5gQALBS/hBG33tABr/etzGVypm0
HJFpDDjc1B/I/3JPomAnLiLMomwYV/tJQZceYeijJRCOko7FMcDkwCwp9qNeTg/K
Fk4TZqQegLmo8eSn7iLpLS1M3zWFUNKMI6pA62ISdO3KDDxudanwGcGXk+nCfaq/
xuFZXtJX22uiJDHm+EH6B4quB/r9cYezzVaLiFiFLRlxgp9W5numcQ4SvVtz3bAA
HUjBlmYB9xPCT5RzqcN8yPGzQ32sQFxapQm9FKDPEqlC+Z2uG6jN6MjY9NE2AC2k
Ebe/6ulVyB1KTnO5h9mUayoJz7zc8osd2U5iusZXn79kwdoTEh2kRM+vF/4hPEWZ
FqMLRLAyqKE6pDOJfgsOo8Gr2oOc12Ng3/PVuqrHM546o+B5WAuu+zWAI/oqnnpr
AM9YGZho4mph0JmTyEdjB4qcWUKskVz/ztUsLYeC0MtYjFVnBbaR02rDW20zDfkk
rH+15QV2yqUs2fKBcYlgZ643fQCOx7hpFVv3WYYZFHqqfHmguB6rTe+3hIe3E/7M
0YWiqNHl6dFDCpIVoU/40vy5fVNyckw1E41yo2mrupyloWPt/7xJBhFZltBparKq
C4MshVNwkCzm5M2gE7oKiQeBsoH22E2HzwMop4TciV4lj9ydG8YTqsL6wPA7R1r4
iSdNUIXNl8s7ZSQXAUUG
=EIRH
-----END PGP SIGNATURE-----

Aaron Kondziela (5):
      Fix CSRF token leak vulnerability
      Escape dashboard saved search descriptions
      Avoid Email::Address denial of service attacks
      Fix timing sidechannel vulnerability in password checking
      Correct name of config option RestrictLoginReferrer

Shawn M Moore (8):
      Avoid potential XSS with several content types
      Merge branch 'security/4.0/csrf-leak' into security/4.2.14-releng
      Merge branch 'security/4.0/email-parse-dos' into security/4.2.14-releng
      Merge branch 'security/4.0/attachment-xss-fix' into security/4.2.14-releng
      Merge branch 'security/4.2/password-timing-attack' into security/4.2.14-releng
      Merge branch 'security/4.0/dash-subscription' into security/4.2.14-releng
      Merge branch 'security/4.2/referrer-login' into security/4.2.14-releng
      Merge branch 'security/4.2.14-releng' into 4.2.14-releng

-----------------------------------------------------------------------


More information about the rt-commit mailing list