Yuxuan 'fishy' Wang | 4f5ad9d | 2016-05-03 16:18:58 -0700 | [diff] [blame] | 1 | = Release notes for Gerrit 2.6.1 |
Shawn Pearce | 7502a46 | 2013-06-22 18:41:28 -0700 | [diff] [blame] | 2 | |
| 3 | There are no schema changes from link:ReleaseNotes-2.6.html[2.6]. |
| 4 | |
Shawn Pearce | 6d7ebc6 | 2015-06-12 16:34:42 -0700 | [diff] [blame] | 5 | link:https://www.gerritcodereview.com/download/gerrit-2.6.1.war[https://www.gerritcodereview.com/download/gerrit-2.6.1.war] |
Shawn Pearce | 7502a46 | 2013-06-22 18:41:28 -0700 | [diff] [blame] | 6 | |
Yuxuan 'fishy' Wang | 4f5ad9d | 2016-05-03 16:18:58 -0700 | [diff] [blame] | 7 | == Bug Fixes |
Shawn Pearce | 7502a46 | 2013-06-22 18:41:28 -0700 | [diff] [blame] | 8 | * Patch JGit security hole |
| 9 | + |
| 10 | The security hole may permit a modified Git client to gain access |
| 11 | to hidden or deleted branches if the user has read permission on |
| 12 | at least one branch in the repository. Access requires knowing a |
| 13 | SHA-1 to request, which may be discovered out-of-band from an issue |
| 14 | tracker or gitweb instance. |