Project

General

Profile

Bug #5745

Entities name rendered as HTML under details page

Added by Brad Buckingham over 6 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
High
Assignee:
Category:
Web UI
Target version:
Difficulty:
hard
Triaged:
Yes
Bugzilla link:
Fixed in Releases:
Found in Releases:

Description

Cloned from https://bugzilla.redhat.com/show_bug.cgi?id=1096189
Description of problem:
GPG key name rendered as HTML under details page. See the name along with Heading "GPG Key" and along with 'Name'

Please see screenshot.

Version-Release number of selected component (if applicable):
Satellite-6.0.3-RHEL-6-20140508.1

How reproducible:
always

Steps to Reproduce:
1. create a gpgkey with <a href='foo'>Click here</a>
2. go to details page
3.

Actual results:
the link'Click here' will be created

Expected results:
the key name should not be rendered as html
it should be like
<a href='foo'>Click here</a>

Additional info:

Associated revisions

Revision 17b36c92 (diff)
Added by Walden Raines about 6 years ago

Fixes #5745/BZ963572: upgrade angular-gettext to fix XSS.

The library Bastion uses for i18n, angular-gettext, was
vulnerable to XSS. This commit upgrades the version of
angular-gettext to one that is no longer vulnerable.

http://projects.theforeman.org/issues/5745
https://bugzilla.redhat.com/show_bug.cgi?id=963572

Revision 0b3e39cd
Added by Walden Raines about 6 years ago

Merge pull request #4512 from waldenraines/5745

Fixes #5745/BZ963572: upgrade angular-gettext to fix XSS.

History

#1 Updated by Brad Buckingham over 6 years ago

  • Triaged set to Yes

#2 Updated by Eric Helms over 6 years ago

  • Target version set to 45
  • Difficulty set to hard

#3 Updated by Eric Helms over 6 years ago

  • Target version changed from 45 to 48

#4 Updated by Walden Raines over 6 years ago

  • Status changed from New to Assigned

#5 Updated by Walden Raines over 6 years ago

  • Priority changed from Normal to High

#6 Updated by Walden Raines over 6 years ago

This is caused by a third party library angular-gettext. I have entered an issue here: https://github.com/rubenv/angular-gettext/issues/75

#7 Updated by Eric Helms over 6 years ago

  • Target version changed from 48 to 49

#8 Updated by Eric Helms over 6 years ago

  • Target version changed from 49 to 54

#9 Updated by The Foreman Bot over 6 years ago

  • Status changed from Assigned to Ready For Testing
  • Pull request https://github.com/Katello/katello/pull/4512 added

#10 Updated by Walden Raines about 6 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100

#11 Updated by Eric Helms about 6 years ago

  • Legacy Backlogs Release (now unused) set to 13

Also available in: Atom PDF