summaryrefslogtreecommitdiff
path: root/doc/news/version_2.48.mdwn
diff options
context:
space:
mode:
authorJoey Hess <joey@kodama.kitenet.net>2008-05-31 20:16:18 -0400
committerJoey Hess <joey@kodama.kitenet.net>2008-05-31 20:16:18 -0400
commitc1289de1eff4c0b4b2cd47e61b2273970e327009 (patch)
treef2f75d16209149452ea8e45f7818b96321de2aa1 /doc/news/version_2.48.mdwn
parent99e5e6dd08ba193046a9e2c349ec5843d31c9c1c (diff)
cve id
Diffstat (limited to 'doc/news/version_2.48.mdwn')
-rw-r--r--doc/news/version_2.48.mdwn1
1 files changed, 1 insertions, 0 deletions
diff --git a/doc/news/version_2.48.mdwn b/doc/news/version_2.48.mdwn
index a0c52f4e8..76dbd7ddc 100644
--- a/doc/news/version_2.48.mdwn
+++ b/doc/news/version_2.48.mdwn
@@ -13,6 +13,7 @@ ikiwiki 2.48 released with [[toggle text="these changes"]]
* Fix security hole that occurred if openid and passwordauth were both
enabled. passwordauth would allow logging in as a known openid, with an
empty password. Closes: #[483770](http://bugs.debian.org/483770)
+ (CVE-2008-0169)
* Add rel=nofollow to edit links. This may prevent some spiders from
pounding on the cgi following edit links.
* passwordauth: If Authen::Passphrase is installed, use it to store