Uploaded image for project: 'Jackrabbit FileVault'
  1. Jackrabbit FileVault
  2. JCRVLT-117

Potential XSS problem in org.apache.jackrabbit.vault.util.HtmlProgressListener

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 3.1.28
    • None
    • None

    Description

      the org.apache.jackrabbit.vault.util.HtmlProgressListener should escape the arguments before it streams them to the stream. the users of the progress listener should not care about the intended output medium.

      Attachments

        Activity

          People

            tripod Tobias Bocanegra
            tripod Tobias Bocanegra
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: