Uploaded image for project: 'Qpid'
  1. Qpid
  2. QPID-4841

[Java Broker] Ensure all data values returned through the REST API are properly sanitised before displaying in HTML to prevent XSS attacks

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 0.22, 0.23
    • Broker-J
    • None

    Description

      To prevent cross site scripting attacks, anywhere where a value which may have been set by a user is displayed through the HTML GUI, we should ensure that the value is properly encoded.

      Attachments

        Activity

          People

            rgodfrey Robert Godfrey
            rgodfrey Robert Godfrey
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: