diff --git a/modules/ROOT/nav.adoc b/modules/ROOT/nav.adoc index 115ee09c15..790eafcc1d 100644 --- a/modules/ROOT/nav.adoc +++ b/modules/ROOT/nav.adoc @@ -411,6 +411,9 @@ ** xref:tinymce-and-cors.adoc[Cross-Origin Resource Sharing (CORS)] * Release information ** xref:release-notes.adoc[Release notes for {productname} 6] +*** {productname} 6.8.5 +**** xref:6.8.5-release-notes.adoc#overview[Overview] +**** xref:6.8.5-release-notes.adoc#security-fix[Security fix] *** {productname} 6.8.4 **** xref:6.8.4-release-notes.adoc#overview[Overview] **** xref:6.8.4-release-notes.adoc#security-fix[Security fix] diff --git a/modules/ROOT/pages/6.8.5-release-notes.adoc b/modules/ROOT/pages/6.8.5-release-notes.adoc new file mode 100644 index 0000000000..197617a5c1 --- /dev/null +++ b/modules/ROOT/pages/6.8.5-release-notes.adoc @@ -0,0 +1,42 @@ += {productname} {release-version} +:release-version: 6.8.5 +:description: Release notes for TinyMCE 6.8.5 +:keywords: releasenotes, new, changes, bugfixes +:page-toclevels: 1 + +include::partial$misc/admon-releasenotes-for-stable.adoc[] + + +[[overview]] +== Overview + +{productname} {release-version} was released for {enterpriseversion} and {cloudname} on Wednesday, October 10^th^, 2024. + +These release notes provide an overview of the changes for {productname} {release-version}, including: + +* xref:security-fix[Security fix] + + +[[security-fix]] +== Security fix + +{productname} {release-version} includes one fix for the following security issue: + +=== Invalid HTML elements within `SVG` elements were not removed +// TINY-11332 + +A https://owasp.org/www-community/attacks/xss/[cross-site scripting] (XSS) vulnerability was discovered in link:https://www.npmjs.com/package/dompurify[DOMPurify] that affects versions of {productname} prior to {release-version} release. The issue was a result of DOMPurify allowing some bypassing which lead to improper sanitization of invalid HTML elements within XML contexts, exploiting parsing inconsistencies between XML and HTML. + +=== Affected Versions + +DOMPurify versions prior to `+<3.1.7+` + +=== Vulnerabilities + +* **Invalid HTML Elements in SVG** (link:https://www.cve.org/CVERecord?id=CVE-2024-45801[CVE-2024-45801]): Allowed invalid HTML elements within `SVG` to bypass sanitization. +* **XML Processing Instruction Bypass**: Exploited differences in XML and HTML parsers regarding Processing Instructions, where XML parsed `+