From e9d45873440f45d7c06e7ec043062f06b6a586a5 Mon Sep 17 00:00:00 2001 From: David Mehren Date: Fri, 15 Jan 2021 20:36:43 +0100 Subject: Bump version to 1.7.2 Signed-off-by: David Mehren --- public/docs/release-notes.md | 9 +++++++++ 1 file changed, 9 insertions(+) (limited to 'public') diff --git a/public/docs/release-notes.md b/public/docs/release-notes.md index 598a5c83..a58018c2 100644 --- a/public/docs/release-notes.md +++ b/public/docs/release-notes.md @@ -1,4 +1,13 @@ # Release Notes +## 1.7.2 2021-01-15 +This release fixes a security issue. We recommend upgrading as soon as possible. +### Security Fixes +- [CVE-2021-21259: Stored XSS in slide mode](https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-44w9-vm8p-3cxw) + An attacker can inject arbitrary JavaScript into a HedgeDoc note. + +### Bugfixes +- Ensure the last line of the markdown editor is not covered by the status bar (thanks to [@mhdrone](https://github.com/mhdrone) for reporting!) + ## 1.7.1 2020-12-27 This release fixes two security issues. We recommend upgrading as soon as possible. ### Security Fixes -- cgit v1.2.3