X-Git-Url: http://git.heureux-cyclage.org/?p=lhc%2Fweb%2Fwiklou.git;a=blobdiff_plain;f=RELEASE-NOTES-1.34;h=3597088498c532005c073106cf5bd95d931fb8da;hp=1313ac2e1793767b7db9746bc6a5b8cda612876a;hb=748c5eae2fd5d897c94c48771161c259941a7488;hpb=43fe3f21d48075ebbabcf0825b1520804ca9175e diff --git a/RELEASE-NOTES-1.34 b/RELEASE-NOTES-1.34 index 1313ac2e17..3597088498 100644 --- a/RELEASE-NOTES-1.34 +++ b/RELEASE-NOTES-1.34 @@ -2,7 +2,7 @@ == MediaWiki 1.34.1 == -THIS IS NOT A RELEASE YET +This is a security and maintenance release of the MediaWiki 1.34 branch. === Changes since MediaWiki 1.34.0 === * (T211450) User: better error message when getActorId fails. @@ -18,6 +18,11 @@ THIS IS NOT A RELEASE YET * Add check for page existence to view.php maintenance script. * (T245149) Fix fetching login token from action=query&meta=tokens on private wikis. +* (T236509) SECURITY: Fix HTML escaping in UserGroupMembership::getLink(). +* (T232932) SECURITY: User content can redirect the logout button to different + URL. +* (T246602) SECURITY: jquery.makeCollapsible allows applying event handler to + any CSS selector. == MediaWiki 1.34.0 ==