blob: 6448f1ccc37ff1fe266891d2b4feaa535862ce5b [file] [log] [blame]
Yuxuan 'fishy' Wang4f5ad9d2016-05-03 16:18:58 -07001= Release notes for Gerrit 2.5.3
Shawn Pearce5534ada2013-05-14 18:33:35 -07002
3Gerrit 2.5.3 is now available:
4
Shawn Pearce6d7ebc62015-06-12 16:34:42 -07005link:https://www.gerritcodereview.com/download/gerrit-2.5.3.war[https://www.gerritcodereview.com/download/gerrit-2.5.3.war]
Shawn Pearce5534ada2013-05-14 18:33:35 -07006
David Pursehouse1f1c7c72013-05-15 10:44:19 +09007There are no schema changes from any of the 2.5.x versions.
Shawn Pearce5534ada2013-05-14 18:33:35 -07008
David Pursehouse1f1c7c72013-05-15 10:44:19 +09009However, if upgrading from a version older than 2.5, follow the upgrade
Shawn Pearce5534ada2013-05-14 18:33:35 -070010procedure in the 2.5 link:ReleaseNotes-2.5.html[Release Notes].
11
Yuxuan 'fishy' Wang4f5ad9d2016-05-03 16:18:58 -070012== Security Fixes
Shawn Pearce5534ada2013-05-14 18:33:35 -070013* Patch vulnerabilities in OpenID client library
14+
15Installations using OpenID for authentication were vulnerable to a
16number of attacks over the network. The openid4java client library
17was identified as the entry point. In this release Gerrit updated to
18the latest 0.9.8 release, which patches the known attack vectors.
19
20No other changes since 2.5.2.