Project

General

Profile

Actions

Bug #14221

closed

we can inject html & javascript in Rudder tables

Bug #14221: we can inject html & javascript in Rudder tables

Added by Nicolas CHARLES about 7 years ago. Updated over 6 years ago.

Status:
Released
Priority:
N/A
Category:
Web - Compliance & node report
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
Fix check:
Regression:

Description

following https://issues.rudder.io/issues/13349 , we can inject, from syslog, js that is evaluated server side on the node compliance/technical log and rules details

exemple: change the component name with

_method_reporting_context("un 'file' 'content' <script>alert('bob');</script>", "/tmp/file_content");

results in a bob showing up


Subtasks 1 (0 open1 closed)

Bug #14231: html on change request list is not correctly escapedReleasedNicolas CHARLESActions

Related issues 3 (0 open3 closed)

Related to Rudder - Bug #13349: Quotes in reports are displayed as &quot; in the web interfaceReleasedVincent MEMBRÉActions
Related to Rudder - Bug #14271: JS in directive name is executed on rule table if the directive is disabledReleasedNicolas CHARLESActions
Related to Rudder - Bug #17698: Tooltips in interface tree evaluate scripts ReleasedFrançois ARMANDActions

Updated by François ARMAND about 7 years ago Actions #1

  • Status changed from New to In progress
  • Assignee set to François ARMAND

Updated by François ARMAND about 7 years ago Actions #2

  • Related to Bug #13349: Quotes in reports are displayed as &quot; in the web interface added

Updated by François ARMAND about 7 years ago Actions #3

  • Status changed from In progress to Pending technical review
  • Assignee changed from François ARMAND to Nicolas CHARLES
  • Pull Request set to https://github.com/Normation/rudder/pull/2122

Updated by Rudder Quality Assistant about 7 years ago Actions #4

  • Assignee changed from Nicolas CHARLES to François ARMAND

Updated by François ARMAND about 7 years ago Actions #5

  • Status changed from Pending technical review to Pending release

Updated by Alexis Mousset about 7 years ago Actions #6

  • Status changed from Pending release to Released
This bug has been fixed in Rudder 4.1.19, 4.3.9 and 5.0.5 which were released today.
Changelog
Changelog
Changelog

Updated by François ARMAND about 7 years ago Actions #7

  • Related to Bug #14271: JS in directive name is executed on rule table if the directive is disabled added

Updated by Vincent MEMBRÉ over 6 years ago Actions #8

  • Private changed from Yes to No

Updated by Nicolas CHARLES over 5 years ago Actions #9

  • Related to Bug #17698: Tooltips in interface tree evaluate scripts added
Actions

Also available in: PDF Atom