aboutsummaryrefslogtreecommitdiff
path: root/doc/security.mdwn
diff options
context:
space:
mode:
authorsmcv <smcv@web>2015-04-14 13:38:13 -0400
committeradmin <admin@branchable.com>2015-04-14 13:38:13 -0400
commit0252e5703daa6b366bac2a1d2dc5983959360f52 (patch)
treeb9b771a0417fdea9cc24181322e679f8483a8261 /doc/security.mdwn
parent8ad932efd511376c3a9889b40a8fb16e2ba5e9a3 (diff)
downloadikiwiki-0252e5703daa6b366bac2a1d2dc5983959360f52.tar
ikiwiki-0252e5703daa6b366bac2a1d2dc5983959360f52.tar.gz
add more details of CVE-2015-2793
Diffstat (limited to 'doc/security.mdwn')
-rw-r--r--doc/security.mdwn8
1 files changed, 4 insertions, 4 deletions
diff --git a/doc/security.mdwn b/doc/security.mdwn
index 6488d7f9e..d5a0266cd 100644
--- a/doc/security.mdwn
+++ b/doc/security.mdwn
@@ -500,9 +500,9 @@ as version 3.20100815.9. An upgrade is recommended for all sites.
## XSS via openid selector
-Raghav Bisht discovered this XSS in the openid selector.
+Raghav Bisht discovered this XSS in the openid selector. ([[!cve CVE-2015-2793]])
The hole was reported on March 24th, a fix was developed on March 27th,
-and the fixed version was released on the 29th. A fix was backported
-to Debian wheezy as version 3.20141016.2. An upgrade is recommended for
-sites using CGI and openid.
+and the fixed version 3.20150329 was released on the 29th. A fix was backported
+to Debian jessie as version 3.20141016.2 and to Debian wheezy as version
+3.20120629.2. An upgrade is recommended for sites using CGI and openid.