diff --git a/data/release-notes/enterprise-server/3-5/17.yml b/data/release-notes/enterprise-server/3-5/17.yml index ea3731c5d8..531eae4e3e 100644 --- a/data/release-notes/enterprise-server/3-5/17.yml +++ b/data/release-notes/enterprise-server/3-5/17.yml @@ -1,8 +1,6 @@ date: '2023-05-09' sections: security_fixes: - - | - **HIGH:** Updated Git to include fixes from 2.39.2, which address [CVE-2023-22490](https://github.com/git/git/security/advisories/GHSA-gw92-x3fm-3g3q) and [CVE-2023-23946](https://github.com/git/git/security/advisories/GHSA-r87m-v37r-cwfh). - | **MEDIUM**: Updated Git to include fixes from 2.40.1. For more information, see [Git security vulnerabilities announced](https://github.blog/2023-04-25-git-security-vulnerabilities-announced-4/) on the GitHub Blog. bugs: diff --git a/data/release-notes/enterprise-server/3-5/19.yml b/data/release-notes/enterprise-server/3-5/19.yml index bbae0d6ab8..dcd98ecb2e 100644 --- a/data/release-notes/enterprise-server/3-5/19.yml +++ b/data/release-notes/enterprise-server/3-5/19.yml @@ -1,8 +1,6 @@ date: '2023-06-20' sections: security_fixes: - - | - **HIGH:** Updated Git to include fixes from 2.39.2, which address [CVE-2023-22490](https://github.com/git/git/security/advisories/GHSA-gw92-x3fm-3g3q) and [CVE-2023-23946](https://github.com/git/git/security/advisories/GHSA-r87m-v37r-cwfh). - | **MEDIUM**: Scoped installation tokens for a GitHub App kept approved permissions after the permissions on the integration installation were downgraded or removed. GitHub has requested CVE ID [CVE-2023-23765](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23765) for this vulnerability, which was reported via the [GitHub Bug Bounty program](https://bounty.github.com). - | diff --git a/data/release-notes/enterprise-server/3-6/13.yml b/data/release-notes/enterprise-server/3-6/13.yml index 3446bf2340..1b84aad712 100644 --- a/data/release-notes/enterprise-server/3-6/13.yml +++ b/data/release-notes/enterprise-server/3-6/13.yml @@ -1,8 +1,6 @@ date: '2023-05-09' sections: security_fixes: - - | - **HIGH:** Updated Git to include fixes from 2.39.2, which address [CVE-2023-22490](https://github.com/git/git/security/advisories/GHSA-gw92-x3fm-3g3q) and [CVE-2023-23946](https://github.com/git/git/security/advisories/GHSA-r87m-v37r-cwfh). - | **MEDIUM**: Updated Git to include fixes from 2.40.1. For more information, see [Git security vulnerabilities announced](https://github.blog/2023-04-25-git-security-vulnerabilities-announced-4/) on the GitHub Blog. bugs: diff --git a/data/release-notes/enterprise-server/3-6/15.yml b/data/release-notes/enterprise-server/3-6/15.yml index d69f6b4f48..8625d9fa70 100644 --- a/data/release-notes/enterprise-server/3-6/15.yml +++ b/data/release-notes/enterprise-server/3-6/15.yml @@ -1,8 +1,6 @@ date: '2023-06-20' sections: security_fixes: - - | - **HIGH:** Updated Git to include fixes from 2.39.2, which address [CVE-2023-22490](https://github.com/git/git/security/advisories/GHSA-gw92-x3fm-3g3q) and [CVE-2023-23946](https://github.com/git/git/security/advisories/GHSA-r87m-v37r-cwfh). - | If a user's request to the instance's API included authentication credentials within a URL parameter, administrators could see the credentials in JSON within the instance's audit log. - Packages have been updated to the latest security versions. diff --git a/data/release-notes/enterprise-server/3-7/10.yml b/data/release-notes/enterprise-server/3-7/10.yml index 341a8d58ce..d02602d7e2 100644 --- a/data/release-notes/enterprise-server/3-7/10.yml +++ b/data/release-notes/enterprise-server/3-7/10.yml @@ -1,8 +1,6 @@ date: '2023-05-09' sections: security_fixes: - - | - **HIGH:** Updated Git to include fixes from 2.39.2, which address [CVE-2023-22490](https://github.com/git/git/security/advisories/GHSA-gw92-x3fm-3g3q) and [CVE-2023-23946](https://github.com/git/git/security/advisories/GHSA-r87m-v37r-cwfh). - | **MEDIUM**: Updated Git to include fixes from 2.40.1. For more information, see [Git security vulnerabilities announced](https://github.blog/2023-04-25-git-security-vulnerabilities-announced-4/) on the GitHub Blog. bugs: diff --git a/data/release-notes/enterprise-server/3-7/12.yml b/data/release-notes/enterprise-server/3-7/12.yml index eb7a1ce779..a0797d7126 100644 --- a/data/release-notes/enterprise-server/3-7/12.yml +++ b/data/release-notes/enterprise-server/3-7/12.yml @@ -1,8 +1,6 @@ date: '2023-06-20' sections: security_fixes: - - | - **HIGH:** Updated Git to include fixes from 2.39.2, which address [CVE-2023-22490](https://github.com/git/git/security/advisories/GHSA-gw92-x3fm-3g3q) and [CVE-2023-23946](https://github.com/git/git/security/advisories/GHSA-r87m-v37r-cwfh). - | **MEDIUM**: Updated Git to include fixes from [2.40.1](https://github.blog/2023-04-25-git-security-vulnerabilities-announced-4/). - |