X-Git-Url: https://git.proxmox.com/?a=blobdiff_plain;f=debian%2Fchangelog;h=6b13e3b0ffd643c4711eaf4d8380be9aff430b79;hb=HEAD;hp=6ef88e4febe35f531f47b5d6bbb6f14bebc043b6;hpb=85f61297734b74591a51f6ca36f303885c03fd5e;p=pve-access-control.git diff --git a/debian/changelog b/debian/changelog index 6ef88e4..cb0e71c 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,28 @@ +libpve-access-control (8.1.4) bookworm; urgency=medium + + * fix #5335: sort ACL entries in user.cfg to make it easier to track changes + + -- Proxmox Support Team Mon, 22 Apr 2024 13:45:22 +0200 + +libpve-access-control (8.1.3) bookworm; urgency=medium + + * user: password change: require confirmation-password parameter so that + anybody gaining local or physical access to a device where a user is + logged in on a Proxmox VE web-interface cannot give them more permanent + access or deny the actual user accessing their account by changing the + password. Note that such an attack scenario means that the attacker + already has high privileges and can already control the resource + completely through another attack. + Such initial attacks (like stealing an unlocked device) are almost always + are outside of the control of our projects. Still, hardening the API a bit + by requiring a confirmation of the original password is to cheap to + implement to not do so. + + * jobs: realm sync: fix scheduled LDAP syncs not applying all attributes, + like comments, correctly + + -- Proxmox Support Team Fri, 22 Mar 2024 14:14:36 +0100 + libpve-access-control (8.1.2) bookworm; urgency=medium * add Sys.AccessNetwork privilege