From e21f09817e62a99f82b5e14236aa2aa29b14a515 Mon Sep 17 00:00:00 2001 From: David Stark Date: Wed, 29 Jan 2020 12:36:11 +0000 Subject: [PATCH] note about open redirect vulneravility --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 767cde7b1f..7bdb02ef93 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -17,7 +17,7 @@ - DigitalOcean provider support added ## Important Notes -N/A +- (Security) Fix for open redirect vulnerability.. a bad actor using `/\` in redirect URIs can redirect a session to another domain ## Breaking Changes