BigW Consortium Gitlab
Fix for HackerOne XSS vulnerability in markdown This is an updated blacklist patch to fix https://dev.gitlab.org/gitlab/gitlabhq/merge_requests/2007. No text is removed. Dangerous schemes/protocols and invalid URIs are left intact but not linked. Fixes https://gitlab.com/gitlab-org/gitlab-ce/issues/23153 See merge request !2015 Signed-off-by: Rémy Coutable <remy@rymai.me>
Name |
Last commit
|
Last update |
---|---|---|
.. | ||
filter | Loading commit data... | |
pipeline | Loading commit data... | |
reference_parser | Loading commit data... | |
cross_project_reference_spec.rb | Loading commit data... | |
filter_array_spec.rb | Loading commit data... | |
note_renderer_spec.rb | Loading commit data... | |
object_renderer_spec.rb | Loading commit data... | |
querying_spec.rb | Loading commit data... | |
redactor_spec.rb | Loading commit data... | |
renderer_spec.rb | Loading commit data... |