Skip to content

Commit d93a35d

Browse files
author
Julien Pivotto
committed
Update CHANGELOG
Signed-off-by: Julien Pivotto <[email protected]>
1 parent 9f088cd commit d93a35d

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

CHANGELOG.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,11 @@
11
## 0.5.1 / 2021-01-15
22

3+
This release includes a side-channel timing security issue that would allow an
4+
attacker to verify if a username is defined in the configuration. #39
5+
36
* [ENHANCEMENT] Cache basic authentication results to significantly improve
47
performance. #32
8+
* [BUGFIX] Prevent user enumeration by timing requests. #39
59

610
## 0.5.0 / 2021-01-13
711

0 commit comments

Comments
 (0)