diff --git a/master/docs/relnotes/index.rst b/master/docs/relnotes/index.rst index 716178e1c..9c065c51c 100644 --- a/master/docs/relnotes/index.rst +++ b/master/docs/relnotes/index.rst @@ -10,6 +10,28 @@ Release Notes .. towncrier release notes start +Buildbot ``1.8.2`` ( ``2019-05-22`` ) +===================================== + +Bug fixes +--------- + +- Fix vulnerability in OAuth where user-submitted authorization token was used for authentication + (https://github.com/buildbot/buildbot/wiki/OAuth-vulnerability-in-using-submitted-authorization-token-for-authentication) + Thanks to Phillip Kuhrt for reporting it. + + +Buildbot ``1.8.1`` ( ``2019-02-02`` ) +===================================== + +Bug fixes +--------- + +- Fix CRLF injection vulnerability with validating user provided redirect parameters + (https://github.com/buildbot/buildbot/wiki/CRLF-injection-in-Buildbot-login-and-logout-redirect-code) + Thanks to ``mik317`` and ``mariadb`` for reporting it. + + Buildbot ``1.8.0`` ( ``2019-01-20`` ) ===================================== diff --git a/master/docs/spelling_wordlist.txt b/master/docs/spelling_wordlist.txt index be3803fde..777b90908 100644 --- a/master/docs/spelling_wordlist.txt +++ b/master/docs/spelling_wordlist.txt @@ -425,6 +425,7 @@ KiB kibibytes kube kubernetes +Kuhrt kv kwargs latin