Change in ovirt-engine[ovirt-engine-3.3]: core: Avoid XSS in RedirectServlet
oschreib at redhat.com
oschreib at redhat.com
Thu Sep 12 08:11:12 UTC 2013
Ofer Schreiber has submitted this change and it was merged.
Change subject: core: Avoid XSS in RedirectServlet
......................................................................
core: Avoid XSS in RedirectServlet
Currently the RedirectServlet composes JavaScript code to show error
messages using text provided by the user in a request parameter. This
text isn't sanitized and thus can be used by maliciuous users to execute
arbitrary JavaScript code. To avoid this situation this patch changes
the servlet so that it doesn't receive any parameter, thus the problem
is completely avoided.
Signed-off-by: Alexander Wels <awels at redhat.com>
Signed-off-by: Juan Hernandez <juan.hernandez at redhat.com>
Change-Id: Ie77e6a063e1522b2e108076a240939ca1dae272e
---
D backend/manager/modules/root/src/main/java/org/ovirt/engine/core/redirect/RedirectServlet.java
A backend/manager/modules/root/src/main/java/org/ovirt/engine/core/redirect/ReportsRedirectServlet.java
M backend/manager/modules/root/src/main/webapp/WEB-INF/web.xml
M packaging/branding/ovirt.brand/welcome_page.template
4 files changed, 48 insertions(+), 112 deletions(-)
Approvals:
Juan Hernandez: Looks good to me, but someone else must approve
Alexander Wels: Verified
Ofer Schreiber: Verified; Looks good to me, approved
--
To view, visit http://gerrit.ovirt.org/19155
To unsubscribe, visit http://gerrit.ovirt.org/settings
Gerrit-MessageType: merged
Gerrit-Change-Id: Ie77e6a063e1522b2e108076a240939ca1dae272e
Gerrit-PatchSet: 1
Gerrit-Project: ovirt-engine
Gerrit-Branch: ovirt-engine-3.3
Gerrit-Owner: Alexander Wels <awels at redhat.com>
Gerrit-Reviewer: Alexander Wels <awels at redhat.com>
Gerrit-Reviewer: Einav Cohen <ecohen at redhat.com>
Gerrit-Reviewer: Juan Hernandez <juan.hernandez at redhat.com>
Gerrit-Reviewer: Ofer Schreiber <oschreib at redhat.com>
More information about the Engine-commits
mailing list