A huge thanks to Florian Krämer for conducting a full security audit on the CakePHP code and Carl Sutton for report and providing a candidate patch.
In addition to the security fix 2.3.4 contains fixes for the following issues:
- Increasing compatibility with old CentOS servers and the way they handle PHP regular expressions
- Preventing pagiation limit from overflowing the max integer value
- Making sure form ids generated in FormHelper::postLink() are actually unique
- Fixed a bug in TextHelper auto link utility
No comments:
Post a Comment