Skip to content

September

Compare
Choose a tag to compare
@stripthis stripthis released this 14 Sep 13:46
· 4542 commits to master since this release
v1.6.5

Security

  • PASSBOLT-2409: Noopener on resource url in password workspace
  • PASSBOLT-2402: XSS on resource url in password workspace

Fixed

  • PASSBOLT-2383: Add + and \ to the list of allowed characters for the Resource fields: name, username and description
  • PASSBOLT-2371: Force the charset of the cake_sessions table in utf8
  • PASSBOLT-2325: As system administrator I shouldn't be able to execute passbolt CLI commands as root
  • PASSBOLT-2397: As system administrator I should see in the healthcheck if app/tmp content and app/webroot/img/public content are writable
  • PASSBOLT-1991: As system administrator I should see in the healthcheck if the server key can be used for encrypting/decrypting