Page MenuHomePhabricator

MediaWiki Security release 1.24.2
Closed, ResolvedPublic

Related Objects

Event Timeline

csteipp claimed this task.
csteipp raised the priority of this task from to Medium.
csteipp updated the task description. (Show Details)
csteipp added a project: acl*security.
csteipp changed the visibility from "Public (No Login Required)" to "Custom Policy".
csteipp changed the edit policy from "All Users" to "Custom Policy".
csteipp changed Security from None to Software security bug.
csteipp added a subscriber: csteipp.

Wondering whether to also add T72510 which has a patch waiting since December.

Apparently phabricator can't upload more than 10MB, so I can't post the full versions yet..

csteipp changed the visibility from "Custom Policy" to "Public (No Login Required)".Mar 31 2015, 9:13 PM
csteipp changed the edit policy from "Custom Policy" to "All Users".
csteipp changed Security from Software security bug to None.
greg added a subscriber: greg.

Thanks Chris.

Was the security audit published somewhere e.g. on or wikitech?

Not yet, but T85862 intends to make it public when all of the issues are resolved.