Release Notes for TYPO3 CMS 8.6.1
This document contains information about TYPO3 CMS 8.6.1 which was released on February 28th, 2017.
This release is a combined bug fix and security release.
Find more details in the security bulletins:
The usual upgrading procedure applies. No database updates are necessary.\ It might be required to clear all caches; the “important actions” section in the TYPO3 Install Tool offers the accordant possibility to do so.
Here is a list of what was fixed since [8.6.0](TYPO3_CMS_8.6.0 "wikilink"):
5ef31ecdde [RELEASE] Release of TYPO3 8.6.1
278af8209d [SECURITY] Prevent possible XSS in Fluid templates
61dd8f4328 [SECURITY] Prevent login of restricted users
1c5765398a [BUGFIX] Don't update passwords if left untouched
TYPO3 Release Packages (the downloadable tarballs and zip files) as well as Git tags are signed using PGP signatures during the automated release process. Besides that, MD5 and SHA2-256 hashes are being generated for these files. Find more details on verifying signatures and hashes in the infrastructure guide.
Example of verifying integrity of tar.gz package of current release:
wget --content-disposition https://get.typo3.org/8.6.1/tar.gz wget --content-disposition https://get.typo3.org/8.6.1/tar.gz.sig gpg --verify typo3_src-8.6.1.tar.gz.sig typo3_src-8.6.1.tar.gz