Skip to content

Commit

Permalink
cherry-pick v2.2.3 changelog entry
Browse files Browse the repository at this point in the history
  • Loading branch information
flavorjones committed Oct 30, 2018
1 parent be0fd3a commit cea7c93
Showing 1 changed file with 9 additions and 0 deletions.
9 changes: 9 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,15 @@ Features:
* Allow greater precision in shorthand CSS values. [#149] (Thanks, @danfstucky!)


## 2.2.3 / 2018-10-30

### Security

Address CVE-2018-16468: Unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

This CVE's public notice is at https://github.com/flavorjones/loofah/issues/154


## Meta / 2018-10-27

The mailing list is now on Google Groups [#146](https://github.com/flavorjones/loofah/issues/146):
Expand Down

0 comments on commit cea7c93

Please sign in to comment.