mirror of
https://github.com/str4d/rage.git
synced 2025-04-05 03:47:46 +03:00
Update changelog with GHSA for security vulnerability
Thanks to ⬡-49016 for reporting this issue.
This commit is contained in:
parent
a82a76a849
commit
0780882307
2 changed files with 9 additions and 11 deletions
|
@ -12,11 +12,10 @@ to 1.0.0 are beta releases.
|
||||||
|
|
||||||
## [0.6.1, 0.7.2, 0.8.2, 0.9.3, 0.10.1, 0.11.1] - 2024-11-18
|
## [0.6.1, 0.7.2, 0.8.2, 0.9.3, 0.10.1, 0.11.1] - 2024-11-18
|
||||||
### Security
|
### Security
|
||||||
- The age plugin protocol previously allowed plugin names that could be
|
- Fixed a security vulnerability that could allow an attacker to execute an
|
||||||
interpreted as file paths. Under certain conditions, this could lead to a
|
arbitrary binary under certain conditions. See GHSA-4fg7-vxc8-qx5w. Plugin
|
||||||
different binary being executed as an age plugin than intended. Plugin names
|
names are now required to only contain alphanumeric characters or the four
|
||||||
are now required to only contain alphanumeric characters or the four special
|
special characters `+-._`. Thanks to ⬡-49016 for reporting this issue.
|
||||||
characters `+-._`.
|
|
||||||
|
|
||||||
## [0.11.0] - 2024-11-03
|
## [0.11.0] - 2024-11-03
|
||||||
### Added
|
### Added
|
||||||
|
|
|
@ -10,13 +10,12 @@ to 1.0.0 are beta releases.
|
||||||
|
|
||||||
## [Unreleased]
|
## [Unreleased]
|
||||||
|
|
||||||
## [0.6.1, 0.7.2, 0.8.2, 0.9.3, 0.10.1, 0.11.1] - 2024-11-18
|
## [0.6.1, 0.7.2, 0.8.2, 0.9.3, 0.10.1, 0.11.1] - 2024-12-18
|
||||||
### Security
|
### Security
|
||||||
- The age plugin protocol previously allowed plugin names that could be
|
- Fixed a security vulnerability that could allow an attacker to execute an
|
||||||
interpreted as file paths. Under certain conditions, this could lead to a
|
arbitrary binary under certain conditions. See GHSA-4fg7-vxc8-qx5w. Plugin
|
||||||
different binary being executed as an age plugin than intended. Plugin names
|
names are now required to only contain alphanumeric characters or the four
|
||||||
are now required to only contain alphanumeric characters or the four special
|
special characters `+-._`. Thanks to ⬡-49016 for reporting this issue.
|
||||||
characters `+-._`.
|
|
||||||
|
|
||||||
## [0.11.0] - 2024-11-03
|
## [0.11.0] - 2024-11-03
|
||||||
### Added
|
### Added
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue