Skip to content

Commit aea3f3b

Browse files
committed
bumped version
1 parent c419575 commit aea3f3b

File tree

2 files changed

+16
-1
lines changed

2 files changed

+16
-1
lines changed

CHANGES.rst

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,21 @@
11
Changes
22
=======
33

4+
1.3.2
5+
-----
6+
7+
Added CSP (Content Security Policy) middleware to stop malicious SVG files from
8+
executing JavaScript. This was possible if:
9+
10+
* Local media storage was enabled
11+
* SVG uploads were allowed from untrusted sources
12+
* When viewing an uploaded SVG in Piccolo Admin, if you open the SVG in a new
13+
tab then it's possible for JavaScript to run.
14+
15+
It's recommended that you upgrade to this version. Thanks to @Skelmis for this.
16+
17+
-------------------------------------------------------------------------------
18+
419
1.3.1
520
-----
621

piccolo_admin/version.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
1.3.1
1+
1.3.2

0 commit comments

Comments
 (0)