APIv4 - Fix resolving pseudoconstants for less-permissioned users
[civicrm-core.git] / release-notes / 5.35.2.md
1 # CiviCRM 5.35.2
2
3 Released April 21, 2021
4
5 - **[Synopsis](#synopsis)**
6 - **[Bugs resolved](#bugs)**
7 - **[Credits](#credits)**
8 - **[Feedback](#feedback)**
9
10 ## <a name="synopsis"></a>Synopsis
11
12 | *Does this version...?* | |
13 | --------------------------------------------------------------- | -------- |
14 | Change the database schema? | no |
15 | Alter the API? | no |
16 | Require attention to configuration options? | no |
17 | Fix problems installing or upgrading to a previous version? | no |
18 | Introduce features? | no |
19 | **Fix bugs?** | **yes** |
20
21 ## <a name="security"></a>Security advisories
22
23 - **[CIVI-SA-2021-08](https://civicrm.org/advisory/civi-sa-2021-08-access-bypass-apiv4)**: Access Bypass in APIv4
24
25 ## <a name="credits"></a>Credits
26
27 Special support from Deutsche Gesellschaft für Internationale Zusammenarbeit
28 GmbH contributed significantly to this release and other contemporaneous
29 security improvements.
30
31 This release was developed by the following authors and reviewers:
32
33 JMA Consulting - Seamus Lee; CiviCRM - Coleman Watts;
34
35 ## <a name="feedback"></a>Feedback
36
37 These release notes are edited by Tim Otten and Andie Hunt. If you'd like to
38 provide feedback on them, please login to https://chat.civicrm.org/civicrm and
39 contact `@agh1`.