Fix bug allowing to execute arbitrary javascript in SVG files.#1251
Fix bug allowing to execute arbitrary javascript in SVG files.#1251noobpk wants to merge 1 commit intoeventum:masterfrom noobpk:master
Conversation
Fix bug allowing to execute arbitrary javascript in SVG files. Bug disclose: https://huntr.dev/bounties/253ebdad-a593-425a-bb91-20da8f3fbae9/
|
@noobpk you should never create pull request from there's short guide how you should contribute: ps: no need to do anything with this PR right now, just informing you. |
|
@noobpk can you add changelog entry? |
Oh sorry, i will do it with the remaining issue. ^^ |
|
@noobpk can you add changelog entry now? as I don't know how to verify this, but the change looks okay, so I'll merge it. once this is merged, you probably need to reset your fork like this (use "master" for "main"): |
How do I do to add changelog? |
You add an entry to CHANGELOG.md under 3.10.8 section |
|
Added changelog myself, and since you created your PR from the |
Add CSP header Closes eventum#1251 Bug Disclosure: https://huntr.dev/bounties/253ebdad-a593-425a-bb91-20da8f3fbae9/ Signed-off-by: Elan Ruusamäe <glen@pld-linux.org>
|
This is released as 3.10.7.1: |
Add CSP header
Bug Disclosure: https://huntr.dev/bounties/253ebdad-a593-425a-bb91-20da8f3fbae9/