Skip to content

Commit

Permalink
chore: Add CVE id to history for 4.6.3
Browse files Browse the repository at this point in the history
  • Loading branch information
rgrove committed Mar 20, 2018
1 parent 5f66eb1 commit f5a2686
Showing 1 changed file with 4 additions and 1 deletion.
5 changes: 4 additions & 1 deletion HISTORY.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@

## 4.6.3 (2018-03-19)

* Fixed an HTML injection vulnerability that could allow XSS.
* [CVE-2018-3740][176]: Fixed an HTML injection vulnerability that could allow
XSS.

When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a
specially crafted HTML fragment can cause libxml2 to generate improperly
Expand All @@ -15,6 +16,8 @@
Many thanks to the Shopify Application Security Team for responsibly reporting
this issue.

[176]:https://github.com/rgrove/sanitize/issues/176

## 4.6.2 (2018-03-19)

* Reduced string allocations to optimize memory usage. [@janklimo - #175][175]
Expand Down

0 comments on commit f5a2686

Please sign in to comment.