From c65043ff2012d302f736a55807195c0406e80f84 Mon Sep 17 00:00:00 2001 From: Tim Otten Date: Tue, 3 Jan 2023 18:32:08 -0800 Subject: [PATCH] release-notes/5.57.0.md - Add security advisories --- release-notes.md | 1 + release-notes/5.57.0.md | 8 ++++++++ 2 files changed, 9 insertions(+) diff --git a/release-notes.md b/release-notes.md index a3c6c4268c..2f03eff17d 100644 --- a/release-notes.md +++ b/release-notes.md @@ -20,6 +20,7 @@ Other resources for identifying changes are: Released January 4, 2023 - **[Synopsis](release-notes/5.57.0.md#synopsis)** +- **[Security advisories](release-notes/5.57.0.md#security)** - **[Features](release-notes/5.57.0.md#features)** - **[Bugs resolved](release-notes/5.57.0.md#bugs)** - **[Miscellany](release-notes/5.57.0.md#misc)** diff --git a/release-notes/5.57.0.md b/release-notes/5.57.0.md index 62c6140841..6ce27d6609 100644 --- a/release-notes/5.57.0.md +++ b/release-notes/5.57.0.md @@ -3,6 +3,7 @@ Released January 4, 2023 - **[Synopsis](#synopsis)** +- **[Security advisories](#security)** - **[Features](#features)** - **[Bugs resolved](#bugs)** - **[Miscellany](#misc)** @@ -20,6 +21,13 @@ Released January 4, 2023 | **Fix problems installing or upgrading to a previous version?** | **yes** | | **Introduce features?** | **yes** | | **Fix bugs?** | **yes** | +| **Fix security vulnerabilities?** | **yes** | + +## Security advisories + +* **[CIVI-SA-2023-01](https://civicrm.org/advisory/civi-sa-2023-01-help-subsystem-rce): RCE via Help Subsystem** +* **[CIVI-SA-2023-02](https://civicrm.org/advisory/civi-sa-2023-02-civievent-xss): XSS via CiviEvent** +* **[CIVI-SA-2023-03](https://civicrm.org/advisory/civi-sa-2023-03-asset-builder-xss): XSS via Asset Builder** ## Features -- 2.25.1