diff options
author | GitLab Bot <gitlab-bot@gitlab.com> | 2021-02-01 18:40:11 +0300 |
---|---|---|
committer | GitLab Bot <gitlab-bot@gitlab.com> | 2021-02-01 18:40:11 +0300 |
commit | 40bd20f425f526076787dc98e64773ec1d3891fa (patch) | |
tree | 305a7d4ddce119f40ba44cd00494ca065e1214d1 | |
parent | 9547eaefda1692ed7912b182958f2dbc146f1833 (diff) |
Add latest changes from gitlab-org/security/gitlab@13-6-stable-eev13.6.6
-rw-r--r-- | CHANGELOG.md | 11 | ||||
-rw-r--r-- | GITALY_SERVER_VERSION | 2 | ||||
-rw-r--r-- | changelogs/unreleased/security-filter-graphql-logs.yml | 5 | ||||
-rw-r--r-- | changelogs/unreleased/security-guest-can-read-tag-from-releases.yml | 5 | ||||
-rw-r--r-- | changelogs/unreleased/security-sanitize-target-branch.yml | 5 | ||||
-rw-r--r-- | changelogs/unreleased/security-ssrf-outbound-request.yml | 5 | ||||
-rw-r--r-- | changelogs/unreleased/secutity-404-difference.yml | 5 | ||||
-rwxr-xr-x[-rw-r--r--] | vendor/gitignore/C++.gitignore | 0 | ||||
-rwxr-xr-x[-rw-r--r--] | vendor/gitignore/Java.gitignore | 0 |
9 files changed, 12 insertions, 26 deletions
diff --git a/CHANGELOG.md b/CHANGELOG.md index d995ed28de8..e520b162a2f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,17 @@ documentation](doc/development/changelog.md) for instructions on adding your own entry. +## 13.6.6 (2021-02-01) + +### Security (5 changes) + +- Filter sensitive GraphQL variables from logs. +- Avoid exposing release links when the user cannot read git-tag/repository. +- Sanitize target branch on MR page. +- Fix DNS rebinding protection bypass when allowing an IP address in Outbound Requests setting. +- Add routes for unmatched url for not-get requests. + + ## 13.6.5 (2021-01-13) ### Security (1 change) diff --git a/GITALY_SERVER_VERSION b/GITALY_SERVER_VERSION index b22e91bfa5d..4c391123315 100644 --- a/GITALY_SERVER_VERSION +++ b/GITALY_SERVER_VERSION @@ -1 +1 @@ -13.6.5
\ No newline at end of file +13.6.6
\ No newline at end of file diff --git a/changelogs/unreleased/security-filter-graphql-logs.yml b/changelogs/unreleased/security-filter-graphql-logs.yml deleted file mode 100644 index 2c70c480289..00000000000 --- a/changelogs/unreleased/security-filter-graphql-logs.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -title: Filter sensitive GraphQL variables from logs -merge_request: -author: -type: security diff --git a/changelogs/unreleased/security-guest-can-read-tag-from-releases.yml b/changelogs/unreleased/security-guest-can-read-tag-from-releases.yml deleted file mode 100644 index a3b9b21d90a..00000000000 --- a/changelogs/unreleased/security-guest-can-read-tag-from-releases.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -title: Avoid exposing release links when the user cannot read git-tag/repository -merge_request: -author: -type: security diff --git a/changelogs/unreleased/security-sanitize-target-branch.yml b/changelogs/unreleased/security-sanitize-target-branch.yml deleted file mode 100644 index 9cf07fbfca4..00000000000 --- a/changelogs/unreleased/security-sanitize-target-branch.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -title: Sanitize target branch on MR page -merge_request: -author: -type: security diff --git a/changelogs/unreleased/security-ssrf-outbound-request.yml b/changelogs/unreleased/security-ssrf-outbound-request.yml deleted file mode 100644 index e67360fdbbf..00000000000 --- a/changelogs/unreleased/security-ssrf-outbound-request.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -title: Fix DNS rebinding protection bypass when allowing an IP address in Outbound Requests setting -merge_request: -author: -type: security diff --git a/changelogs/unreleased/secutity-404-difference.yml b/changelogs/unreleased/secutity-404-difference.yml deleted file mode 100644 index 0c09f2da9df..00000000000 --- a/changelogs/unreleased/secutity-404-difference.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -title: Add routes for unmatched url for not-get requests -merge_request: -author: -type: security diff --git a/vendor/gitignore/C++.gitignore b/vendor/gitignore/C++.gitignore index 259148fa18f..259148fa18f 100644..100755 --- a/vendor/gitignore/C++.gitignore +++ b/vendor/gitignore/C++.gitignore diff --git a/vendor/gitignore/Java.gitignore b/vendor/gitignore/Java.gitignore index a1c2a238a96..a1c2a238a96 100644..100755 --- a/vendor/gitignore/Java.gitignore +++ b/vendor/gitignore/Java.gitignore |