Skip to content

Commit d63a968

Browse files
committed
Updated CHANGES for v0.20100408.1
1 parent fc0982a commit d63a968

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

CHANGES.txt

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,9 @@ Changes
33

44
OpenConferenceWare stable releases and changes included, with latest at top:
55

6+
* v0.20100408.1
7+
- FIXED proposal creation: the acts-as-taggable 1.1.9 plugin was buggy, reverted to 1.1.5.
8+
69
* v0.20100408
710
- SECURITY flaw fixed: The buggy "restful_authentication" plugin used by OpenConferenceWare and OpenProposals let users without email addresses that had used the "remember me" feature to sometimes login as other users without email addresses that had also used the "remember me" feature during the same day. All known operators running this software were notified and sent patches in advance of this notification. Because authentication was handled by OpenID, a compromise could not be escalated and there was no password to steal, the worst thing an attacker could do was edit your profile and proposals.
811
- FIXED handling of multiple events: reworked layout, header, menu, favorites, tracks, etc.

0 commit comments

Comments
 (0)