-
-
Notifications
You must be signed in to change notification settings - Fork 7
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Problem: Potential Cross-site scripting #44
Comments
Greetings! Thank you for reporting this issue. Had overlooked that validation. |
Hi Would you mind publishing a CVE for this? |
I actually do not know how to publish a CVE. Would have to read into it.. |
Yes, absolutely right! |
That would be great if you can setup a security policy for the repo you own here https://github.com/ansibleguy/webui/security. This would allow users to draft a report on their own. You will then only need to approve and publish it. Ref: https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/publishing-a-repository-security-advisory# |
Alright. Have added the policy and |
Fix looks good. I am no longer able to reproduce the vulnerability. Please go ahead and publish a security advisory for this. |
Here you go: GHSA-927p-xrc2-x2gj Thank you again for reporting it. Have a nice day |
Versions
latest
Scope
Backend (API)
Issue
Report.pdf
The text was updated successfully, but these errors were encountered: