← Back to team overview

yahoo-eng-team team mailing list archive

[Bug 1463698] Re: XSS

 

Sounds like escaping of content needs to happen where the content is
embedded. Swift just gives you back what you gave it.

Adding Horizon, marking invalid for Swift.

** Also affects: horizon
   Importance: Undecided
       Status: New

** Changed in: swift
       Status: Incomplete => Invalid

-- 
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Dashboard (Horizon).
https://bugs.launchpad.net/bugs/1463698

Title:
  XSS

Status in OpenStack Dashboard (Horizon):
  New
Status in OpenStack Security Advisory:
  Won't Fix
Status in OpenStack Object Storage (swift):
  Invalid

Bug description:
  2.14.2

To manage notifications about this bug go to:
https://bugs.launchpad.net/horizon/+bug/1463698/+subscriptions