From: Abhishek Lekshmanan Date: Fri, 24 Apr 2020 10:34:59 +0000 (+0200) Subject: doc: releases: add release notes for v14.2.9 X-Git-Tag: v16.1.0~2516^2~1 X-Git-Url: http://git-server-git.apps.pok.os.sepia.ceph.com/?a=commitdiff_plain;h=42388336534a9ee21e9db684bd71680a7f2de94a;p=ceph.git doc: releases: add release notes for v14.2.9 Signed-off-by: Abhishek Lekshmanan --- diff --git a/doc/releases/nautilus.rst b/doc/releases/nautilus.rst index 87fb0bba2a5b..0c28e42b566c 100644 --- a/doc/releases/nautilus.rst +++ b/doc/releases/nautilus.rst @@ -1,3 +1,16 @@ +v14.2.9 Nautilus +================ + +This is the ninth bugfix release of Nautilus. This release fixes a +couple of security issues in RGW & Messenger V2. We recommend all users +to upgrade to this release. + +Notable Changes +--------------- + +- CVE-2020-1759: Fixed nonce reuse in msgr V2 secure mode +- CVE-2020-1760: Fixed XSS due to RGW GetObject header-splitting + v14.2.8 Nautilus ================