Project

General

Profile

Actions

Bug #56133

closed

Manager > Object Gateway > Users does not HTML encode "Full Name" field

Added by Matthew Darwin almost 2 years ago. Updated about 1 year ago.

Status:
Resolved
Priority:
Normal
Category:
-
Target version:
-
% Done:

0%

Source:
Community (user)
Tags:
backport_processed
Backport:
quincy,pacific
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

Manager > Object Gateway > Users does not HTML encode "Full Name" field

Set the Full name of a user to "<b>bold</b> name". You will see the "bold" part actually in bold.


Files

html-injection.png (25.4 KB) html-injection.png Matthew Darwin, 06/20/2022 09:22 PM

Related issues 2 (0 open2 closed)

Copied to Dashboard - Backport #56946: pacific: Manager > Object Gateway > Users does not HTML encode "Full Name" fieldResolvedPedro González Gómez Actions
Copied to Dashboard - Backport #56947: quincy: Manager > Object Gateway > Users does not HTML encode "Full Name" fieldResolvedPedro González Gómez Actions
Actions #1

Updated by Casey Bodley almost 2 years ago

  • Project changed from rgw to Dashboard
Actions #2

Updated by Nizamudeen A almost 2 years ago

  • Status changed from New to Triaged
  • Assignee set to Pedro González Gómez
Actions #3

Updated by Pedro González Gómez almost 2 years ago

  • Pull request ID set to 46996
Actions #4

Updated by Pedro González Gómez over 1 year ago

  • Backport set to quincy,pacific
Actions #5

Updated by Pedro González Gómez over 1 year ago

  • Status changed from Triaged to Pending Backport
Actions #6

Updated by Backport Bot over 1 year ago

  • Copied to Backport #56946: pacific: Manager > Object Gateway > Users does not HTML encode "Full Name" field added
Actions #7

Updated by Backport Bot over 1 year ago

  • Copied to Backport #56947: quincy: Manager > Object Gateway > Users does not HTML encode "Full Name" field added
Actions #8

Updated by Backport Bot over 1 year ago

  • Tags set to backport_processed
Actions #9

Updated by Pedro González Gómez about 1 year ago

  • Status changed from Pending Backport to Resolved
Actions

Also available in: Atom PDF