diff --git a/changelog.html b/changelog.html index fad07088da..82d83c4b49 100644 --- a/changelog.html +++ b/changelog.html @@ -46,9 +46,11 @@
1.12.1 (to be determined)
Use the form below to enable or disable the REST API and - configure the authentication.
- <% if (success) { %> @@ -136,6 +133,29 @@ } %> + <% + if (RESTServicePlugin.isAllowedIPsCheckSpoofable()) { + %> +| Access is restricted to specific IP addresses, but the admin console is + configured to determine the client address from forwarded HTTP headers (such as X-Forwarded-For), + without a list of trusted proxies. Any client can bypass the IP address check by sending such a header. + Configure the addresses of your reverse proxies as trusted proxies on the + Admin Console Access page. + | +
Use the form below to enable or disable the REST API and + configure the authentication.
+