CVE-2020-15856 - Web interface can be abused by XSS attack. Attackers can supply subversive http links containing malicious javascript code. Such links were not controlled properly, so attackers can potentially force users to submit actions which were not intended. Some actions which can be done via web UI can be destructive, so updating to this version is highly recommended.
Metadata Update from @tkopecek: - Custom field Size adjusted to None - Issue tagged with: bug
Metadata Update from @tkopecek: - Issue private status set to: False (was: True)
Commit 2be8600b fixes this issue
Commit 6d4831a6 fixes this issue
This issue has been migrated to Fedora Forge: https://forge.fedoraproject.org/koji/koji/issues/2645
Please continue any further discussion there.