X-Git-Url: http://www.privoxy.org/gitweb/?p=privoxy.git;a=blobdiff_plain;f=ChangeLog;h=867cb5d41053df473b702b81a1bd7fb056b2e3c0;hp=6a00f3f5276185af2b28d8f186f994828fa801f8;hb=0727fcb2601279e3568ee2e7d216931f6fc9abfe;hpb=0d04dd411e43b85c164e15e504db49607be72b3b diff --git a/ChangeLog b/ChangeLog index 6a00f3f5..867cb5d4 100644 --- a/ChangeLog +++ b/ChangeLog @@ -4,7 +4,7 @@ ChangeLog for Privoxy *** Version 3.0.33 stable *** - Security/Reliability: - cgi_error_no_template(): Encode the template name to prevent - XSS (cross-side scripting) when Privoxy is configured to servce + XSS (cross-site scripting) when Privoxy is configured to servce the user-manual itself. Commit 0e668e9409c. OVE-20211102-0001. CVE-2021-44543. Reported by: Artem Ivanov