stable
  • Fix JavaScript errors

  • New upstream security release 1.7.17

  • http://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.17/
  • Resolves: CVE-2013-4519
  • Security Fixes:
  • Fixed XSS vulnerabilities for the 'Branch' field and uploaded file captions.
  • Added a 'X-Frame-Options' header to prevent clickjacking.
  • New Features:
  • Remove the need for SSH keys for GitHub repositories.
  • Improved validation for GitHub repositories.
  • Added support for permissions on Local Sites.
  • Performance Improvements:
  • Reduced query counts on all pages.
  • Reduced query counts in the web API when returning empty lists.
  • Extensibility:
  • Extensions using the configure_extension view an now pass in a custom template_name pointing to a template for the configuration page, if it needs additional customization.
  • Enabling, disabling or reconfiguring extensions will now invalidate the caches for pages, ensuring that hooks will take affect.
  • Extension configuration now works properly on subdirectory installs.
  • Bug Fixes:
  • Fixed showing private review requests on a submitter page.
  • The description for submitted or discarded review requests is now shown on the diff viewer.
  • Discarding, reopening and then closing a review request no longer makes the review request private.
  • Fixed a naming conflict with older PyCrypto packages, such as the default package on CentOS 6.4.
  • Users with the 'can_change_status' permission no longer need the 'can_edit_reviewrequest' permission in order to close or reopen review requests.
  • Switching a repository from using a hosting service to Custom no longer reverts back to the hosting service.
  • Fixed editing a repository if its associated hosting service can't be loaded (such as if an extension providing that hosting service is disabled).
  • Many diff validation errors weren't being shown on the New Review Request page, generating 500 errors instead.
  • Fixed caching issues with the Blocks field on review requests.
  • Editing JSON text fields in the administration UI now works, validates, and won't result in warnings in the log.
  • Fixed breakages with looking up URLs internally with Local Sites.

This update has been submitted for testing by sgallagh.

9 years ago

sgallagh has edited this update. New build(s): python-djblets-0.7.23-1.el6.

9 years ago

This update is currently being pushed to the Fedora EPEL 6 testing updates repository.

9 years ago

This update has been pushed to testing

9 years ago

sgallagh has edited this update. New build(s): ReviewBoard-1.7.18-1.el6. Removed build(s): ReviewBoard-1.7.17-1.el6.1.

9 years ago

This update has been submitted for testing by sgallagh.

9 years ago

This update is currently being pushed to the Fedora EPEL 6 testing updates repository.

9 years ago

This update has been pushed to testing

9 years ago

This update has reached 14 days in testing and can be pushed to stable now if the maintainer wishes

9 years ago

This update has been submitted for stable by sgallagh.

9 years ago

This update is currently being pushed to the Fedora EPEL 6 stable updates repository.

9 years ago

This update has been pushed to stable

9 years ago

Please login to add feedback.

Metadata
Type
security
Karma
0
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
9 years ago
in testing
9 years ago
in stable
9 years ago
modified
9 years ago
BZ#1027010 CVE-2013-4519 ReviewBoard: two XSS vulnerabilities
0
0
BZ#1027107 ReviewBoard-1.7.17 is available
0
0
BZ#1030019 diffs not visible in 1.7.17-1
0
0

Automated Test Results