yahoo-eng-team team mailing list archive
-
yahoo-eng-team team
-
Mailing list archive
-
Message #07571
[Bug 1260525] Re: Incomplete XSS fix for ossa/1247675
Bug is now a public non-vulnerability, tagged as security hardening, no
advisory. Thanks!
** Information type changed from Private Security to Public
** Tags added: security
** Changed in: ossa
Status: Incomplete => Invalid
--
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Dashboard (Horizon).
https://bugs.launchpad.net/bugs/1260525
Title:
Incomplete XSS fix for ossa/1247675
Status in OpenStack Dashboard (Horizon):
Confirmed
Status in OpenStack Security Advisories:
Invalid
Bug description:
The patch for https://bugs.launchpad.net/ossa/+bug/1247675 did not
completely fix the reported issue.
It failed to completely remove the use of html.strip_tags, which is
not intended to be a security function, and does not properly sanitize
output.
https://github.com/openstack/horizon/blob/master/openstack_dashboard/dashboards/project/volumes/tables.py#L254
To manage notifications about this bug go to:
https://bugs.launchpad.net/horizon/+bug/1260525/+subscriptions