Update changelog with GHSA for security vulnerability

Thanks to ⬡-49016 for reporting this issue.
This commit is contained in:
Jack Grigg 2024-12-18 15:17:33 +00:00
parent a82a76a849
commit 0780882307
2 changed files with 9 additions and 11 deletions

View file

@ -12,11 +12,10 @@ to 1.0.0 are beta releases.
## [0.6.1, 0.7.2, 0.8.2, 0.9.3, 0.10.1, 0.11.1] - 2024-11-18 ## [0.6.1, 0.7.2, 0.8.2, 0.9.3, 0.10.1, 0.11.1] - 2024-11-18
### Security ### Security
- The age plugin protocol previously allowed plugin names that could be - Fixed a security vulnerability that could allow an attacker to execute an
interpreted as file paths. Under certain conditions, this could lead to a arbitrary binary under certain conditions. See GHSA-4fg7-vxc8-qx5w. Plugin
different binary being executed as an age plugin than intended. Plugin names names are now required to only contain alphanumeric characters or the four
are now required to only contain alphanumeric characters or the four special special characters `+-._`. Thanks to ⬡-49016 for reporting this issue.
characters `+-._`.
## [0.11.0] - 2024-11-03 ## [0.11.0] - 2024-11-03
### Added ### Added

View file

@ -10,13 +10,12 @@ to 1.0.0 are beta releases.
## [Unreleased] ## [Unreleased]
## [0.6.1, 0.7.2, 0.8.2, 0.9.3, 0.10.1, 0.11.1] - 2024-11-18 ## [0.6.1, 0.7.2, 0.8.2, 0.9.3, 0.10.1, 0.11.1] - 2024-12-18
### Security ### Security
- The age plugin protocol previously allowed plugin names that could be - Fixed a security vulnerability that could allow an attacker to execute an
interpreted as file paths. Under certain conditions, this could lead to a arbitrary binary under certain conditions. See GHSA-4fg7-vxc8-qx5w. Plugin
different binary being executed as an age plugin than intended. Plugin names names are now required to only contain alphanumeric characters or the four
are now required to only contain alphanumeric characters or the four special special characters `+-._`. Thanks to ⬡-49016 for reporting this issue.
characters `+-._`.
## [0.11.0] - 2024-11-03 ## [0.11.0] - 2024-11-03
### Added ### Added