Merge branch 'jk/maint-gitweb-xss'
Fixes an XSS vulnerability in gitweb. * jk/maint-gitweb-xss: gitweb: escape html in rss title
This commit is contained in:
@ -8054,6 +8054,7 @@ sub git_feed {
|
||||
$feed_type = 'history';
|
||||
}
|
||||
$title .= " $feed_type";
|
||||
$title = esc_html($title);
|
||||
my $descr = git_get_project_description($project);
|
||||
if (defined $descr) {
|
||||
$descr = esc_html($descr);
|
||||
|
Reference in New Issue
Block a user