-
-
Notifications
You must be signed in to change notification settings - Fork 699
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Security flaw, to be fixed in 0.56.1 and 0.57 #1360
Labels
Comments
simonw
added a commit
that referenced
this issue
Jun 5, 2021
simonw
added a commit
that referenced
this issue
Jun 5, 2021
Closed
I've released fixes in both 0.56.1 and 0.57. |
Worth noting that I found this issue myself, and to my knowledge it has not been uncovered by anyone else prior to the patch being released. |
simonw
added a commit
to simonw/datasette-auth-passwords
that referenced
this issue
Jun 5, 2021
Now depends on datasette>=0.56.1 Refs simonw/datasette#1360
# for free
to join this conversation on GitHub.
Already have an account?
# to comment
See security advisory here for details: GHSA-xw7c-jx9m-xh5g - the
?_trace=1
debugging option was not correctly escaping its JSON output, resulting in a reflected cross-site scripting vulnerability.The text was updated successfully, but these errors were encountered: