X-Git-Url: https://sipb.mit.edu/gitweb.cgi/ikiwiki.git/blobdiff_plain/d5c964508f159c7209b98771bed1ec8df4c952a0..a05a15731dff7daa170b289c062ebf5d1357c4e8:/doc/security.mdwn?ds=sidebyside diff --git a/doc/security.mdwn b/doc/security.mdwn index 29ae7d4b3..fc9937288 100644 --- a/doc/security.mdwn +++ b/doc/security.mdwn @@ -372,8 +372,8 @@ parties. Cross Site Request Forging could be used to constuct a link that would change a logged-in user's password or other preferences if they clicked on the link. It could also be used to construct a link that would cause a wiki -page to be modified by a logged-in user. +page to be modified by a logged-in user. ([[cve CVE-2008-0165]]) These holes were discovered on 10 April 2008 and fixed the same day with the release of ikiwiki 2.42. A fix was also backported to Debian etch, as -version 1.33.4. I recommend upgrading to one of these versions. +version 1.33.5. I recommend upgrading to one of these versions.