CustomFields - Improve metadata for custom_group_extends
[civicrm-core.git] / release-notes / 5.19.2.md
index 2766086b252117a71f4603ef30a5fd138cce7a87..4c9e256bfab8ea0a76f87531a5e4a6447099aff7 100644 (file)
@@ -20,12 +20,12 @@ Released November 20, 2019
 
 ## <a name="security"></a>Security advisories
 
-- **[CIVI-SA-2019-19](https://civicrm.org/advisory/civi-sa-2019-19-sqli-in-dedupefind)**: SQLI in "dedupefind"
-- **[CIVI-SA-2019-20](https://civicrm.org/advisory/civi-sa-2019-20-privilege-escalation-via-leaked-key)**: Privilege escalation via leaked key
-- **[CIVI-SA-2019-21](https://civicrm.org/advisory/civi-sa-2019-21-poi-saved-search-and-report-instance-apis)**: POI via "Saved Search" and "Report Instance" APIs
-- **[CIVI-SA-2019-22](https://civicrm.org/advisory/civi-sa-2019-22-xss-in-dashboard-titles)**: XSS in dashboard titles
-- **[CIVI-SA-2019-23](https://civicrm.org/advisory/civi-sa-2019-23-incorrect-storage-encoding-for-apiv4)**: Incorrect storage encoding for APIv4
-- **[CIVIEXT-SA-2019-02](https://civicrm.org/advisory/civiext-sa-2019-02-xss-in-civicase-v5-extension)**: XSS in CiviCase v5 extension
+- **[CIVI-SA-2019-19](https://civicrm.org/advisory/civi-sa-2019-19-sqli-in-dedupefind): SQL injection in "dedupefind"**
+- **[CIVI-SA-2019-20](https://civicrm.org/advisory/civi-sa-2019-20-privilege-escalation-via-leaked-key): Privilege escalation via leaked key**
+- **[CIVI-SA-2019-21](https://civicrm.org/advisory/civi-sa-2019-21-poi-saved-search-and-report-instance-apis): PHP object injection via "Saved Search" and "Report Instance" APIs**
+- **[CIVI-SA-2019-22](https://civicrm.org/advisory/civi-sa-2019-22-xss-in-dashboard-titles): Cross-site scripting in dashboard titles**
+- **[CIVI-SA-2019-23](https://civicrm.org/advisory/civi-sa-2019-23-incorrect-storage-encoding-for-apiv4): Incorrect storage encoding for APIv4**
+- **[CIVIEXT-SA-2019-02](https://civicrm.org/advisory/civiext-sa-2019-02-xss-in-civicase-v5-extension): Cross-site scripting in CiviCase v5 extension**
 
 ## <a name="bugs"></a>Bugs resolved
 
@@ -39,7 +39,9 @@ Released November 20, 2019
 This release was developed by the following people, who participated in
 various stages of reporting, analysis, development, review, and testing:
 
-Alan Dixon of Blackfly Solutions; Coleman Watts of CiviCRM; Daniel Compton of
-Armadillo Sec Ltd; Eileen McNaughton of Wikimedia Foundation; Kevin Cristiano of
-Tadpole Collective; Mark Burdett of Electronic Frontier Foundation; Patrick Figel
-of Greenpeace CEE; Seamus Lee of Australian Greens; Tim Otten of CiviCRM
+Alan Dixon of Blackfly Solutions; Coleman Watts of CiviCRM; Daniel Compton
+of Armadillo Sec Ltd; Dave D; Eileen McNaughton of Wikimedia Foundation;
+Karin Gerritsen of Semper IT; Kevin Cristiano of Tadpole Collective; Mark
+Burdett of Electronic Frontier Foundation; Morgan Robinson of Palante
+Technology Cooperative; Patrick Figel of Greenpeace CEE; Seamus Lee of
+Australian Greens; Tim Otten of CiviCRM