#2645 XSS web vulnerability
Closed: Fixed by tkopecek. Opened by tkopecek.

CVE-2020-15856 - Web interface can be abused by XSS attack. Attackers can supply subversive http links containing malicious javascript code. Such links were not controlled properly, so attackers can potentially force users to submit actions which were not intended. Some actions which can be done via web UI can be destructive, so updating to this version is highly recommended.


Metadata Update from @tkopecek:
- Custom field Size adjusted to None
- Issue tagged with: bug

Metadata Update from @tkopecek:
- Issue private status set to: False (was: True)

Commit 2be8600b fixes this issue

Commit 6d4831a6 fixes this issue

This issue has been migrated to Fedora Forge:
https://forge.fedoraproject.org/koji/koji/issues/2645

Please continue any further discussion there.

Metadata
Related Pull Requests