A new version of Geeklog has been made available. Version 1.8.1 ships with jQuery 1.6.3, which fixes a possible XSS in that JavaScript library, which shouldn't have affected Geeklog itself, but may potentially exist in add-ons that make extensive use of jQuery. Geeklog 1.8.1 also fixes two cases of information leakage, where the OAuth consumer key and secret were exposed when enabling the “rootdebug” option (which is off by default). Also, the MS SQL driver was displaying full details of SQL errors by default.
Other changes in this release:
There were no changes in the database, the themes or the language files in Geeklog 1.8.1 (over 1.8.0), so upgrades should be relatively straighforward.