aboutsummaryrefslogtreecommitdiff
path: root/doc/security.mdwn
diff options
context:
space:
mode:
authorJoey Hess <joey@kodama.kitenet.net>2008-05-31 20:16:18 -0400
committerJoey Hess <joey@kodama.kitenet.net>2008-05-31 20:16:18 -0400
commitc1289de1eff4c0b4b2cd47e61b2273970e327009 (patch)
treef2f75d16209149452ea8e45f7818b96321de2aa1 /doc/security.mdwn
parent99e5e6dd08ba193046a9e2c349ec5843d31c9c1c (diff)
downloadikiwiki-c1289de1eff4c0b4b2cd47e61b2273970e327009.tar
ikiwiki-c1289de1eff4c0b4b2cd47e61b2273970e327009.tar.gz
cve id
Diffstat (limited to 'doc/security.mdwn')
-rw-r--r--doc/security.mdwn2
1 files changed, 1 insertions, 1 deletions
diff --git a/doc/security.mdwn b/doc/security.mdwn
index b2e076ec4..57cac719f 100644
--- a/doc/security.mdwn
+++ b/doc/security.mdwn
@@ -403,7 +403,7 @@ passwords in cleartext over the net to log in, either.
This hole allowed ikiwiki to accept logins using empty passwords, to openid
accounts that didn't use a password. It was introduced in version 1.34, and
fixed in version 2.48. The [bug](http://bugs.debian.org/483770) was
-discovered on 30 May 2008 and fixed the same day.
+discovered on 30 May 2008 and fixed the same day. ([[cve CVE-2008-0169]])
I recommend upgrading to 2.48 immediatly if your wiki allows both password
and openid logins.