aboutsummaryrefslogtreecommitdiffstats
path: root/NEWS
diff options
context:
space:
mode:
authorMark Sapiro <mark@msapiro.net>2018-03-08 17:33:07 -0800
committerMark Sapiro <mark@msapiro.net>2018-03-08 17:33:07 -0800
commit21eafd3e46083eded01f67ea828bc7b46ffb3f07 (patch)
treefb8227f504f69e8423595805f21bf1c7b7b53261 /NEWS
parente61719889de7b570adb19af5e223c66f1e09e8bc (diff)
downloadmailman2-21eafd3e46083eded01f67ea828bc7b46ffb3f07.tar.gz
mailman2-21eafd3e46083eded01f67ea828bc7b46ffb3f07.tar.xz
mailman2-21eafd3e46083eded01f67ea828bc7b46ffb3f07.zip
Added a few more badword checks to Utils.suspiciousHTML().
Added validation of GUI updates to host_name.
Diffstat (limited to 'NEWS')
-rw-r--r--NEWS5
1 files changed, 5 insertions, 0 deletions
diff --git a/NEWS b/NEWS
index 4e707a72..1541b414 100644
--- a/NEWS
+++ b/NEWS
@@ -7,6 +7,11 @@ Here is a history of user visible changes to Mailman.
2.1.27 (xx-xxx-xxxx)
+ Security
+
+ - Existing protections against malicious listowners injecting evil
+ scripts into listinfo pages have had a few more checks added.
+
Bug fixes and other patches
- Bad values in a list's topics will no longer break everything that