-----
- Release Notes for Archiva 1.3.5
+ Release Notes for Archiva 1.3.6
-----
-Release Notes for Archiva 1.3.5
+Release Notes for Archiva 1.3.6
- The Apache Archiva team would like to announce the release of Archiva 1.3.5. Archiva is {{{http://archiva.apache.org/download.html}
+ The Apache Archiva team would like to announce the release of Archiva 1.3.6. Archiva is {{{http://archiva.apache.org/download.html}
available for download from the web site}}.
Archiva is an application for managing one or more remote repositories, including administration, artifact handling, browsing and searching.
* Security Vulnerabilities
- * A CSRF security vulnerability (CVE-2010-3449) is present in 1.3.2 and earlier.
-
- * An XSS security vulnerability (CVE-2011-0533) is present in 1.3.3 and earlier.
+ * A remote code execution (CVE-2010-1870) vulnerability has been reported against 1.3.5
+ and earlier versions.
- * Additional CSRF (CVE-2011-1026) and XSS security (CVE-2011-1077) vulnerabilities have been reported against 1.3.4
+ * CSRF (CVE-2011-1026) and XSS security (CVE-2011-1077) vulnerabilities have been reported against 1.3.4
and earlier versions.
+ * An XSS security vulnerability (CVE-2011-0533) is present in 1.3.3 and earlier.
+
+ * A CSRF security vulnerability (CVE-2010-3449) is present in 1.3.2 and earlier.
+
It is important that users using lower versions of Archiva upgrade to this version (or higher).
See {{{http://archiva.apache.org/security.html} Archiva Security}} for more details.
* Release Notes
- The Archiva 1.3.5 feature set can be seen in the {{{tour/index.html} feature tour}}.
+ The Archiva 1.3.6 feature set can be seen in the {{{tour/index.html} feature tour}}.
+
+* Changes in Archiva 1.3.6
+
+ Released: <<7 January 2013>>
+
+** Bug
+
+ * [MRM-1738] - defaultStack requires a stronger blacklist of parameter names in the param interceptor
* Changes in Archiva 1.3.5