From ef9e73e67f80ca21aaf3c10c11f04869ebf7bc3b Mon Sep 17 00:00:00 2001
From: Fridolin Somers
Date: Wed, 24 Feb 2021 08:19:59 +0100
Subject: [PATCH] [RMaint] Add Bug 27604 security fix to 20.11.03 release notes
---
misc/release_notes/release_notes_20_11_03.html | 5 +++--
misc/release_notes/release_notes_20_11_03.md | 5 +++--
2 files changed, 6 insertions(+), 4 deletions(-)
diff --git a/misc/release_notes/release_notes_20_11_03.html b/misc/release_notes/release_notes_20_11_03.html
index 03c42ea753..bcdb650b6a 100644
--- a/misc/release_notes/release_notes_20_11_03.html
+++ b/misc/release_notes/release_notes_20_11_03.html
@@ -26,16 +26,17 @@ website for the Koha project is:
Koha 20.11.03 is a bugfix/maintenance release.
-It includes 2 new features, 22 enhancements, 74 bugfixes, 1 security fix.
+It includes 2 new features, 22 enhancements, 74 bugfixes, 2 security fixes.
System requirements
You can learn about the system components (like OS and database) for running Koha here.
-Security fix
+Security fixes
- [27715] Possibly SQL injection in virtualshelves
+- [27604] PatronSelfRegistrationLibraryList can be bypassed
New features
diff --git a/misc/release_notes/release_notes_20_11_03.md b/misc/release_notes/release_notes_20_11_03.md
index eccfdea7b9..788abb197e 100644
--- a/misc/release_notes/release_notes_20_11_03.md
+++ b/misc/release_notes/release_notes_20_11_03.md
@@ -19,15 +19,16 @@ Installation instructions can be found at:
Koha 20.11.03 is a bugfix/maintenance release.
-It includes 2 new features, 22 enhancements, 74 bugfixes, 1 security fix.
+It includes 2 new features, 22 enhancements, 74 bugfixes, 2 security fixes.
### System requirements
You can learn about the system components (like OS and database) for running Koha [here](https://wiki.koha-community.org/wiki/System_requirements_and_recommendations).
-## Security fix
+## Security fixes
- [[27715]](http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=27715) Possibly SQL injection in virtualshelves
+- [[27604]](http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=27604) PatronSelfRegistrationLibraryList can be bypassed
## New features
--
2.39.5