Commit a674e131 authored by Luke Bennett's avatar Luke Bennett

Update CHANGELOG.md for 10.3.7

[ci skip]
parent 00b28eed
...@@ -207,6 +207,16 @@ entry. ...@@ -207,6 +207,16 @@ entry.
- Use a background migration for issues.closed_at. - Use a background migration for issues.closed_at.
## 10.3.7 (2018-02-05)
### Security (4 changes)
- Fix namespace access issue for GitHub, BitBucket, and GitLab.com project importers.
- Fix stored XSS in code blocks that ignore highlighting.
- Fix wilcard protected tags protecting all branches.
- Restrict Todo API mark_as_done endpoint to the user's todos only.
## 10.3.6 (2018-01-22) ## 10.3.6 (2018-01-22)
### Fixed (17 changes, 2 of them are from the community) ### Fixed (17 changes, 2 of them are from the community)
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment