mirror of
				https://github.com/zulip/zulip.git
				synced 2025-11-04 05:53:43 +00:00 
			
		
		
		
	version: Update version and changelog after 4.10 release.
This commit is contained in:
		@@ -121,6 +121,23 @@ log][commit-log] for an up-to-date list of raw changes.
 | 
			
		||||
 | 
			
		||||
## Zulip 4.x series
 | 
			
		||||
 | 
			
		||||
## Zulip 4.10 -- 2022-02-25
 | 
			
		||||
 | 
			
		||||
- CVE-2022-21706: Reusable invitation links could be improperly used
 | 
			
		||||
  for other organizations.
 | 
			
		||||
- CVE-2021-3967: Enforce that regenerating an API key must be done
 | 
			
		||||
  with an API key, not a cookie. Thanks to nhiephon
 | 
			
		||||
  (twitter.com/\_nhiephon) for their responsible disclosure of this
 | 
			
		||||
  vulnerability.
 | 
			
		||||
- Fixed a bug with the `reindex-textual-data` tool, where it would
 | 
			
		||||
  sometimes fail to find the libraries it needed.
 | 
			
		||||
- Pin PostgreSQL to 10.19, 11.14, 12.9, 13.5 or 14.1 to avoid a
 | 
			
		||||
  regression which caused deploys with PGroonga enabled to
 | 
			
		||||
  unpredictably fail database queries with the error
 | 
			
		||||
  `variable not found in subplan target list`.
 | 
			
		||||
- Fix ARM64 support; however, the wal-g binary is not yet supported on
 | 
			
		||||
  ARM64 (zulip/zulip#21070).
 | 
			
		||||
 | 
			
		||||
## Zulip 4.9 -- 2022-01-24
 | 
			
		||||
 | 
			
		||||
- CVE-2021-43799: Remote execution of code involving RabbitMQ.
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user