diff options
author | Joey Hess <joey@kodama.kitenet.net> | 2008-04-20 15:25:51 -0400 |
---|---|---|
committer | Joey Hess <joey@kodama.kitenet.net> | 2008-04-20 15:25:51 -0400 |
commit | 3912a9f5e9e3936822b434862cb7877ea7378beb (patch) | |
tree | 803b440907db8a7d8b7b5e76de3d821bea3e413f /doc | |
parent | e62f3f8f951cca752eeebebba310dc51df392516 (diff) | |
download | ikiwiki-3912a9f5e9e3936822b434862cb7877ea7378beb.tar ikiwiki-3912a9f5e9e3936822b434862cb7877ea7378beb.tar.gz |
add CVE link
Diffstat (limited to 'doc')
-rw-r--r-- | doc/security.mdwn | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/doc/security.mdwn b/doc/security.mdwn index bbbc98e1f..fc9937288 100644 --- a/doc/security.mdwn +++ b/doc/security.mdwn @@ -372,7 +372,7 @@ parties. Cross Site Request Forging could be used to constuct a link that would change a logged-in user's password or other preferences if they clicked on the link. It could also be used to construct a link that would cause a wiki -page to be modified by a logged-in user. +page to be modified by a logged-in user. ([[cve CVE-2008-0165]]) These holes were discovered on 10 April 2008 and fixed the same day with the release of ikiwiki 2.42. A fix was also backported to Debian etch, as |