aboutsummaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Bump version to 4.2.4release-4.2.4bugzilla-4.2.4Dave Lawrence2012-11-132-3/+3
* Bug 790296 (CVE-2012-4189): [SECURITY] Field values are not escaped correctly...Frédéric Buclin2012-11-132-2/+2
* Bug 808845 (CVE-2012-5475): [SECURITY] Security vulnerability in YUI's swfsto...Frédéric Buclin2012-11-131-0/+0
* Bug 781850 (CVE-2012-4198): [SECURITY] Do not leak the existence of groups wh...Frédéric Buclin2012-11-132-6/+21
* Bug 802204 (CVE-2012-4197): [SECURITY] Marking an attachment you cannot see a...Frédéric Buclin2012-11-132-5/+1
* Bug 731178 (CVE-2012-4199): [SECURITY] field-events.js.tmpl discloses product...Frédéric Buclin2012-11-132-9/+21
* Back out the last checkin, it was already thereFrédéric Buclin2012-11-031-3/+0
* Bug 805647: One more item for the 4.2.4 release notesFrédéric Buclin2012-11-031-0/+3
* Bug 804505: Oracle crashes when typing "word1 word2" in QuickSearch with "ORA...Frédéric Buclin2012-11-033-9/+10
* Bug 806012: Installation docs need to be updated with instructions for bzrFrédéric Buclin2012-11-022-6/+6
* Fix typoFrédéric Buclin2012-11-021-1/+1
* Bug 807937: Fix PODKoosha Khajeh Moogahi2012-11-021-6/+7
* Bug 805647: Release notes for Bugzilla 4.2.4Frédéric Buclin2012-10-261-3/+50
* Bug 610767: contrib/convert-workflow.pl should add transitions from RESOLVED ...Frédéric Buclin2012-10-251-3/+46
* Bug 531243: Bugzilla crashes on show_bug if it's hit while a custom field is ...Frédéric Buclin2012-10-191-1/+9
* Bug 780053: Oracle crashes when listing keywords or flags in buglistsDavid Taylor2012-10-191-9/+13
* Bug 799721: PostgreSQL 9.2 requires DBD::Pg 2.19.3Frédéric Buclin2012-10-161-4/+5
* Bug 781314: The behavior of tags changedFrédéric Buclin2012-10-141-11/+5
* Fix typoFrédéric Buclin2012-10-131-1/+1
* s/sortey/sortkey/gFrédéric Buclin2012-10-121-2/+2
* Bug 790129: Bugzilla->fields returns fields in random order (the sortkey is i...Simon Green2012-10-121-2/+3
* Bug 793826: Prevent private web service methods from being calledKoosha Khajeh Moogahi2012-10-121-1/+3
* Bug 798994: Fix incorrect double escaping when displaying saved queries URLsSimon Green2012-10-111-1/+1
* Bug 753635: Allow editing local see also even if you cannot edit the other bugSimon Green2012-10-091-3/+7
* Bug 652047: checksetup.pl fails to compile/run if the Voting extension is ena...Frédéric Buclin2012-10-082-1/+33
* Bug 790909: Editing dependencies from the "Change Several Bugs at Once" page ...Frédéric Buclin2012-10-041-1/+1
* Bug 788098: Queries involving group substitution crash when usevisibilitygrou...Frédéric Buclin2012-10-042-6/+14
* Bug 794389: There is no field named 'actual_time' when generating reportsFrédéric Buclin2012-10-041-0/+4
* Bug 757935: Bugs with resolution MOVED cannot be editedFrédéric Buclin2012-10-031-1/+3
* Bug 793893: Tabular reports crash when no format parameter is definedFrédéric Buclin2012-09-293-7/+5
* Bug 761046: Don't redirect when hitting buglist.cgi directly to avoid duplica...Byron Jones2012-09-171-1/+0
* Update POD to fix bustage in Perl 5.16.1Frédéric Buclin2012-09-142-0/+7
* Bug 680771 - Send X-XSS-Protection header for XSS prevention/blockingReed Loden2012-09-121-0/+4
* Bug 790215 - Flag names are not properly escaped when displayed on confirm us...Reed Loden2012-09-112-2/+1
* Bug 671612: Send "X-Content-Type-Options: nosniff" with every responseMatt Selsky2012-09-093-4/+5
* Bug 786889: Add missing 'Summary (first 60 chars)' header to CSV outputMatt Tyson2012-09-031-0/+1
* Bumped version post-releaseDave Lawrence2012-08-301-1/+1
* Bump version to 4.2.3release-4.2.3bugzilla-4.2.3Dave Lawrence2012-08-302-3/+3
* Bug 785470: (CVE-2012-3981) [SECURITY] Missing escaping of the username can l...Reed Loden2012-08-301-0/+2
* Bug 785522: [SECURITY] Block access to templates in extensions/Frédéric Buclin2012-08-301-1/+1
* Bug 731156: [Oracle] Adding or removing a DB column does not handle SERIAL co...Frédéric Buclin2012-08-302-29/+97
* Bug 786351: Release notes for Bugzilla 4.2.3Frédéric Buclin2012-08-301-0/+41
* Bug 772620: Ignore empty strings in the CC listFrédéric Buclin2012-08-291-0/+2
* Bug 786310: Remove tokens when saving the default queryByron Jones2012-08-291-0/+2
* Fix more bustage caused by Bug 772953Byron Jones2012-08-291-4/+6
* Fix bustage caused by Bug 772953Byron Jones2012-08-291-1/+4
* Bug 772953: Remove the token from buglist urlsByron Jones2012-08-294-3/+24
* Bug 785917: Custom field descriptions are not properly escaped when displayed...Frédéric Buclin2012-08-272-2/+1
* Bug 559539: [Oracle] whine.pl sets run_next incorrectly due to CURRENT_DATEDavid Taylor2012-08-261-3/+5
* Bug 783786: PostgreSQL databases can be created with the wrong encodingFrédéric Buclin2012-08-211-0/+10