blob: ece0bdab28f3051adae1c57a85f6fef150eb72af [file] [log] [blame]
= Release notes for Gerrit 2.4.3
There are no schema changes from link:ReleaseNotes-2.4.2.html[2.4.2].
== Bug Fixes
* Patch JGit security hole
The security hole may permit a modified Git client to gain access
to hidden or deleted branches if the user has read permission on
at least one branch in the repository. Access requires knowing a
SHA-1 to request, which may be discovered out-of-band from an issue
tracker or gitweb instance.