diff --git a/misc/release_notes/release_notes_23_05_14.md b/misc/release_notes/release_notes_23_05_14.md new file mode 100644 index 0000000000..ad0512b73f --- /dev/null +++ b/misc/release_notes/release_notes_23_05_14.md @@ -0,0 +1,219 @@ +# RELEASE NOTES FOR KOHA 23.05.14 +13 Aug 2024 + +Koha is the first free and open source software library automation +package (ILS). Development is sponsored by libraries of varying types +and sizes, volunteers, and support companies from around the world. The +website for the Koha project is: + +- [Koha Community](http://koha-community.org) + +Koha 23.05.14 can be downloaded from: + +- [Download](http://download.koha-community.org/koha-23.05.14.tar.gz) + +Installation instructions can be found at: + +- [Koha Wiki](http://wiki.koha-community.org/wiki/Installation_Documentation) +- OR in the INSTALL files that come in the tarball + +Koha 23.05.14 is a bugfix/maintenance release. + +It includes 2 enhancements, 6 bugfixes. + +**System requirements** + +You can learn about the system components (like OS and database) needed for running Koha on the [community wiki](https://wiki.koha-community.org/wiki/System_requirements_and_recommendations). + + +#### Security bugs + +- [37323](http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=37323) Remote-Code-Execution (RCE) in picture-upload.pl +- [37370](http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=37370) opac-export.pl can be used even if exporting disabled +- [37464](http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=37464) Remote Code Execution in barcode function leads to reverse shell +- [37466](http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=37466) Reflected Cross Site Scripting +- [37488](http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=37488) Filepaths not validated in ZIP upload to picture-upload.pl +- [37508](http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=37508) SQL reports should not show patron password hash if queried + + **Sponsored by** *Reserve Bank of New Zealand* + +## Bugfixes + +### Acquisitions + +#### Critical bugs fixed + +- [37533](http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=37533) Invalid query when receiving an order + +### Fines and fees + +#### Critical bugs fixed + +- [37255](http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=37255) Creating default waiting hold cancellation policy for all patron categories and itemtypes breaks Koha + + **Sponsored by** *Koha-Suomi Oy* + +## Documentation + +The Koha manual is maintained in Sphinx. The home page for Koha +documentation is + +- [Koha Documentation](http://koha-community.org/documentation/) +As of the date of these release notes, the Koha manual is available in the following languages: + +- [Chinese (Traditional)](https://koha-community.org/manual/23.05/zh_Hant/html/) (75%) +- [English](https://koha-community.org/manual/23.05//html/) (100%) +- [English (USA)](https://koha-community.org/manual/23.05/en/html/) +- [French](https://koha-community.org/manual/23.05/fr/html/) (47%) +- [German](https://koha-community.org/manual/23.05/de/html/) (37%) +- [Greek](https://koha-community.org/manual/23.05//html/) (48%) +- [Hindi](https://koha-community.org/manual/23.05/hi/html/) (76%) + +The Git repository for the Koha manual can be found at + +- [Koha Git Repository](https://gitlab.com/koha-community/koha-manual) + +## Translations + +Complete or near-complete translations of the OPAC and staff +interface are available in this release for the following languages: +