diff --git a/docs/CHANGELOG.asciidoc b/docs/CHANGELOG.asciidoc index 46cd7ef4de284..28e7644e121c0 100644 --- a/docs/CHANGELOG.asciidoc +++ b/docs/CHANGELOG.asciidoc @@ -92,10 +92,16 @@ This section summarizes the changes in each release. == {kib} 5.6.13 [float] -=== Enhancement +=== Bug Fixes + +Security:: +* Fixes an issue with reporting that could potentially send authentication +credentials to third parties (CVE-2018-17245). See +https://www.elastic.co/blog/elastic-support-alert-kibana-reporting-vulnerability[this blog post]. {pull}24177[#24177] +* Fixes an issue with the console API that might allow arbitrary files to be +included from the system (CVE-2018-17246). See +https://www.elastic.co/community/security[Security issues]. {pull}24398[#24398] -Operations:: -* Upgrades the version of ChromeDriver to 2.42.1 {pull}23648[#23648] [[release-notes-5.6.12]] == {kib} 5.6.12