-
-
Notifications
You must be signed in to change notification settings - Fork 7
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Problem: Potential Cross-site scripting #44
Comments
Greetings! Thank you for reporting this issue. Had overlooked that validation. |
Hi Would you mind publishing a CVE for this? |
I actually do not know how to publish a CVE. Would have to read into it.. |
Yes, absolutely right! |
That would be great if you can setup a security policy for the repo you own here https://github.com/ansibleguy/webui/security. This would allow users to draft a report on their own. You will then only need to approve and publish it. Ref: https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/publishing-a-repository-security-advisory# |
Alright. Have added the policy and |
Fix looks good. I am no longer able to reproduce the vulnerability. Please go ahead and publish a security advisory for this. |
Here you go: GHSA-927p-xrc2-x2gj Thank you again for reporting it. Have a nice day |
Versions
latest
Scope
Backend (API)
Issue
Report.pdf
The text was updated successfully, but these errors were encountered: