Branch: refs/heads/stable-15.5.x
Home:
https://github.com/xwiki/xwiki-platform
Commit: da177c3c972e797d92c1a31e278f946012c41b56
https://github.com/xwiki/xwiki-platform/commit/da177c3c972e797d92c1a31e278f…
Author: pjeanjean <pierre.jeanjean(a)xwiki.com>
Date: 2023-11-02 (Thu, 02 Nov 2023)
Changed paths:
M
xwiki-platform-core/xwiki-platform-oldcore/src/main/java/com/xpn/xwiki/render/DefaultVelocityManager.java
M
xwiki-platform-core/xwiki-platform-oldcore/src/test/java/com/xpn/xwiki/render/DefaultVelocityManagerTest.java
Log Message:
-----------
XWIKI-21478: Improve rights check of template macros
Commit: 6ed57dbc5a18a202ba76dddc43965cc978bb93d6
https://github.com/xwiki/xwiki-platform/commit/6ed57dbc5a18a202ba76dddc4396…
Author: Thomas Mortagne <thomas.mortagne(a)gmail.com>
Date: 2023-11-03 (Fri, 03 Nov 2023)
Changed paths:
M
xwiki-platform-core/xwiki-platform-oldcore/src/main/java/com/xpn/xwiki/render/DefaultVelocityManager.java
M
xwiki-platform-core/xwiki-platform-oldcore/src/test/java/com/xpn/xwiki/render/DefaultVelocityManagerTest.java
Log Message:
-----------
Merge pull request from GHSA-cv55-v6rw-7r5v
XWIKI-21478: Remote code execution from account via custom skins support (15.5.x)
Compare:
https://github.com/xwiki/xwiki-platform/compare/18758136560c...6ed57dbc5a18