From cc7b15fe935d41aab85918eb7ae7c0ef81f8bfb0 Mon Sep 17 00:00:00 2001 From: GitLab Release Tools Bot Date: Mon, 29 Jul 2019 14:48:20 +0000 Subject: Update CHANGELOG.md for 11.11.7 [ci skip] --- CHANGELOG.md | 15 +++++++++++++++ 1 file changed, 15 insertions(+) (limited to 'CHANGELOG.md') diff --git a/CHANGELOG.md b/CHANGELOG.md index e2882bce1bd..d93cc182c62 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -644,6 +644,21 @@ entry. - Moves snowplow to CE repo. +## 11.11.7 + +### Security (9 changes) + +- Restrict slash commands to users who can log in. +- Patch XSS issue in wiki links. +- Filter merge request params on the new merge request page. +- Fix Server Side Request Forgery mitigation bypass. +- Show badges if pipelines are public otherwise default to project permissions. +- Do not allow localhost url redirection in GitHub Integration. +- Do not show moved issue id for users that cannot read issue. +- Use source project as permissions reference for MergeRequestsController#pipelines. +- Drop feature to take ownership of trigger token. + + ## 11.11.4 (2019-06-26) ### Fixed (3 changes) -- cgit v1.2.1