Files @ 81057be7a5c1
Branch filter:

Location: kallithea/docs/changelog.rst - annotation

81057be7a5c1 200 B text/prs.fallenstein.rst Show Source Show as Raw Download as Raw
Søren Løvborg
auth: properly invoke PermFunctions (CVE-2016-3114)

This fixes a vulnerability that allowed logged-in users to edit or
delete open pull requests associated with any repository to which
they had read access, plus a related vulnerability allowing logged-in
users to delete any comment from any repository, provided they could
determine the comment ID and had read access to just one repository.
.. _changelog:

=========
Changelog
=========

Kallithea project doesn't keep its changelog here.  We refer you to our `Mercurial logs`__.


.. __: https://kallithea-scm.org/repos/kallithea/changelog