Actions
Bug #21471
closedBug #21442: Various XSS vulnerabilities in the interface
XSS in node details tooltip and node column title in 7.0
Pull Request:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
Description
Some more JS not escaped in rudder 7.0:
- column title
- node details info available in tooltip
Updated by François ARMAND over 2 years ago
- Status changed from New to In progress
- Assignee set to François ARMAND
Updated by François ARMAND over 2 years ago
- Status changed from In progress to Pending technical review
- Assignee changed from François ARMAND to Alexis Mousset
- Pull Request set to https://github.com/Normation/rudder/pull/4396
Updated by Anonymous over 2 years ago
- Status changed from Pending technical review to Pending release
Applied in changeset rudder|8175a283c1624badb367136bf1a895c721efbaa3.
Updated by Alexis Mousset over 2 years ago
- Target version changed from 7.0.6 to 7.0.5
Updated by Alexis Mousset over 2 years ago
- Status changed from Pending release to Released
This bug has been fixed in Rudder 7.0.5 and 7.1.3 which were released today.
Actions