dd1ef1d114
The release notes on master were updated to use links to the new download site, but those updates were not reflected on the stable-2.6 branch. Also the release note for 2.6.1 is missing on stable-2.6, but instead the release note for 2.6.2 (which does not exist) is there. And there are several older release notes missing. Sync the release notes from master to make them consistent. Change-Id: I8facc676aeff754f092a5a9a7bf69345229a55f0
17 lines
606 B
Plaintext
17 lines
606 B
Plaintext
Release notes for Gerrit 2.6.1
|
|
==============================
|
|
|
|
There are no schema changes from link:ReleaseNotes-2.6.html[2.6].
|
|
|
|
link:https://gerrit-releases.storage.googleapis.com/gerrit-2.6.1.war[https://gerrit-releases.storage.googleapis.com/gerrit-2.6.1.war]
|
|
|
|
Bug Fixes
|
|
---------
|
|
* Patch JGit security hole
|
|
+
|
|
The security hole may permit a modified Git client to gain access
|
|
to hidden or deleted branches if the user has read permission on
|
|
at least one branch in the repository. Access requires knowing a
|
|
SHA-1 to request, which may be discovered out-of-band from an issue
|
|
tracker or gitweb instance.
|