Bug #21471
closed
Bug #21442: Various XSS vulnerabilities in the interface
XSS in node details tooltip and node column title in 7.0
Added by François ARMAND over 2 years ago.
Updated over 1 year ago.
Description
Some more JS not escaped in rudder 7.0:
- column title
- node details info available in tooltip
- Status changed from New to In progress
- Assignee set to François ARMAND
- Status changed from In progress to Pending technical review
- Assignee changed from François ARMAND to Alexis Mousset
- Pull Request set to https://github.com/Normation/rudder/pull/4396
- Status changed from Pending technical review to Pending release
- Target version changed from 7.0.6 to 7.0.5
- Status changed from Pending release to Released
This bug has been fixed in Rudder 7.0.5 and 7.1.3 which were released today.
- Private changed from Yes to No
Also available in: Atom
PDF