]> git.apps.os.sepia.ceph.com Git - ceph-ci.git/commitdiff
doc: releases: add release notes for v14.2.9
authorAbhishek Lekshmanan <abhishek@suse.com>
Fri, 24 Apr 2020 10:34:59 +0000 (12:34 +0200)
committerAbhishek Lekshmanan <abhishek@suse.com>
Fri, 24 Apr 2020 10:34:59 +0000 (12:34 +0200)
Signed-off-by: Abhishek Lekshmanan <abhishek@suse.com>
doc/releases/nautilus.rst

index 87fb0bba2a5b5c46da899962a00d8aac25fd1a22..0c28e42b566c65d5f59198e882b98e8a5396af34 100644 (file)
@@ -1,3 +1,16 @@
+v14.2.9 Nautilus
+================
+
+This is the ninth bugfix release of Nautilus. This release fixes a
+couple of security issues in RGW & Messenger V2. We recommend all users
+to upgrade to this release.
+
+Notable Changes
+---------------
+
+- CVE-2020-1759: Fixed nonce reuse in msgr V2 secure mode
+- CVE-2020-1760: Fixed XSS due to RGW GetObject header-splitting
+
 v14.2.8 Nautilus
 ================