Skip to content

Commit

Permalink
Update CHANGELOG.md
Browse files Browse the repository at this point in the history
  • Loading branch information
nilmerg committed Aug 17, 2020
1 parent 5e596c4 commit b012efc
Showing 1 changed file with 21 additions and 0 deletions.
21 changes: 21 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,27 @@ Please make sure to always read our [Upgrading](doc/80-Upgrading.md) documentati

## What's New

### What's New in Version 2.8.2

**Notice**: This is a security release. It is recommended to immediately upgrade to this release.

You can find all issues related to this release on the respective [milestone](https://github.com/Icinga/icingaweb2/milestone/62?closed=1).

#### Path Traversal Vulnerability

The vulnerability in question allows an attacker to access arbitrary files which are readable by the process running
Icinga Web 2. Technical details can be found at the corresponding [CVE-2020-24368](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24368)
and in the issue below.

* Possible path traversal when serving static image files [#4226](https://github.com/Icinga/icingaweb2/issues/4226)

#### Broken Negated Filters with PostgreSQL

We've also included a small non-security related fix. Searching for e.g. `servicegroup!=support` leads to an error
instead of the desired result when using a PostgreSQL database.

* Single negated membership filter fails with PostgreSQL [#4196](https://github.com/Icinga/icingaweb2/issues/4196)

### What's New in Version 2.8.1

You can find all issues related to this release on the respective [milestone](https://github.com/Icinga/icingaweb2/milestone/61?closed=1).
Expand Down

0 comments on commit b012efc

Please sign in to comment.