Skip to content

escape xss#352

Merged
sonots merged 1 commit intogeminabox:masterfrom
ooooooo-q:escape_xss
May 29, 2021
Merged

escape xss#352
sonots merged 1 commit intogeminabox:masterfrom
ooooooo-q:escape_xss

Conversation

@ooooooo-q
Copy link
Copy Markdown
Contributor

I confirmed that when I uploaded a gem file with the author, name, platform, and description, it became XSS because it was not escaped in each view.

This is a fix in gemirro.
PierreRambaud/gemirro@8acfb9c#diff-d3aacd45db679dbc7d7cc26ec48eb3531ef20c73e13d280179f68679b0aa3365

@sonots
Copy link
Copy Markdown
Member

sonots commented May 29, 2021

thx

@sonots sonots merged commit 4a32e23 into geminabox:master May 29, 2021
@ooooooo-q ooooooo-q deleted the escape_xss branch May 31, 2021 09:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants