提交 160ed1d7 编写于 作者: G GitLab Release Tools Bot

Update CHANGELOG.md for 11.2.6

[ci skip]
上级 74843bb2
......@@ -547,6 +547,17 @@ entry.
- Creates Vue component for artifacts block on job page.
## 11.2.6 (2018-10-26)
### Security (5 changes)
- Escape entity title while autocomplete template rendering to prevent XSS. !2558
- Fix XSS in merge request source branch name.
- Redact personal tokens in unsubscribe links.
- Persist only SHA digest of PersonalAccessToken#token.
- Prevent SSRF attacks in HipChat integration.
## 11.2.5 (2018-10-05)
### Security (3 changes)
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册