Details
Description
Scripts can be injected into the job status page as the diagnostics field is
not sanitized. Whatever string you set there will show up to the jobs page as it is ... ie. if you put any script commands, they will be executed in the browser of the user who is opening the page.
We need escaping the diagnostic string in order to not run the scripts.
Attachments
Attachments
Issue Links
- breaks
-
YARN-1975 Used resources shows escaped html in CapacityScheduler and FairScheduler page
- Closed