]> source.dussan.org Git - vaadin-framework.git/commitdiff
Added mention of security fixes in release notes 6.7.0.rc1
authorJonatan Kronqvist <jonatan.kronqvist@itmill.com>
Wed, 28 Sep 2011 10:42:06 +0000 (10:42 +0000)
committerJonatan Kronqvist <jonatan.kronqvist@itmill.com>
Wed, 28 Sep 2011 10:42:06 +0000 (10:42 +0000)
svn changeset:21406/svn branch:6.7

WebContent/release-notes.html

index 97a1d6020af24b1fb4bb46bc0d09d977add6fd58..6bf511c2da8711ac2a6ef1386097a2f4864ee25a 100644 (file)
@@ -43,6 +43,8 @@
                <ul>
                        <li><a href="#overview">Package contents</a>
                        </li>
+                       <li><a href="#security-fixes">Security fixes in Vaadin @version@</a>
+                       </li>
                        <li><a href="#enhancements">Enhancements in Vaadin @version@</a>
                        </li>
                        <li><a href="#fixes">Fixes in Vaadin @version@</a>
                        </ul>
                </p>
 
+               <h2 id="security-fixes">Security fixes in Vaadin @version@</h2>
+               <p>Vaadin @version@ incorporates fixes for the following security issues:</p>
+    <ul>
+        <li><a href="http://dev.vaadin.com/ticket/7669">#7669</a> CSRF/XSS vulnerability through separator injection</li>
+        <li><a href="http://dev.vaadin.com/ticket/7670">#7670</a> Directory traversal vulnerability</li>
+        <li><a href="http://dev.vaadin.com/ticket/7671">#7671</a> Contributory XSS: Possibility to inject HTML/JavaScript in system error messages</li>
+        <li><a href="http://dev.vaadin.com/ticket/7672">#7672</a> Contributory XSS: possibility for injection in certain components</li>
+    </ul>
 
                <h2 id="enhancements">Enhancements in Vaadin @version@</h2>
                <p>