Skip to content

Commit 7fb6c1e

Browse files
committed
Prepare changelog for v1.5.15
1 parent 97586aa commit 7fb6c1e

File tree

1 file changed

+16
-0
lines changed

1 file changed

+16
-0
lines changed

CHANGELOG.md

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,19 @@
1+
Changes in [1.5.15](https://github.com/vector-im/riot-web/releases/tag/v1.5.15) (2020-04-01)
2+
============================================================================================
3+
[Full Changelog](https://github.com/vector-im/riot-web/compare/v1.5.14...v1.5.15)
4+
5+
## Security notice
6+
7+
The `jitsi.html` widget wrapper introduced in Riot 1.5.14 could be used to extract user data by tricking the user into adding a custom widget or opening a link in the browser used to run Riot. Jitsi widgets created through Riot UI do not pose a risk and do not need to be recreated.
8+
9+
It is important to purge any copies of Riot 1.5.14 so that the vulnerable `jitsi.html` wrapper from that version is no longer accessible.
10+
11+
## All changes
12+
13+
* Upgrade React SDK to 2.3.1 for Jitsi fixes
14+
* Fix popout support for jitsi widgets
15+
[\#12980](https://github.com/vector-im/riot-web/pull/12980)
16+
117
Changes in [1.5.14](https://github.com/vector-im/riot-web/releases/tag/v1.5.14) (2020-03-30)
218
============================================================================================
319
[Full Changelog](https://github.com/vector-im/riot-web/compare/v1.5.14-rc.1...v1.5.14)

0 commit comments

Comments
 (0)