From 160ed1d7a1d56135427dfa68980f9653e41bd907 Mon Sep 17 00:00:00 2001 From: GitLab Release Tools Bot Date: Fri, 26 Oct 2018 07:37:07 +0000 Subject: Update CHANGELOG.md for 11.2.6 [ci skip] --- CHANGELOG.md | 11 +++++++++++ 1 file changed, 11 insertions(+) (limited to 'CHANGELOG.md') diff --git a/CHANGELOG.md b/CHANGELOG.md index 09ed9b216aa..842b9f983c3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -547,6 +547,17 @@ entry. - Creates Vue component for artifacts block on job page. +## 11.2.6 (2018-10-26) + +### Security (5 changes) + +- Escape entity title while autocomplete template rendering to prevent XSS. !2558 +- Fix XSS in merge request source branch name. +- Redact personal tokens in unsubscribe links. +- Persist only SHA digest of PersonalAccessToken#token. +- Prevent SSRF attacks in HipChat integration. + + ## 11.2.5 (2018-10-05) ### Security (3 changes) -- cgit v1.2.1