[ 
https://issues.apache.org/jira/browse/STORM-408?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14098786#comment-14098786
 ] 

Parth Brahmbhatt commented on STORM-408:
----------------------------------------

I tried the same thing in firefox 24.0 , same result. I think upgrading to the 
newest version should fix the issue for you. Not sure what's the policy on 
fixing bugs/security vulnerabilities on older versions. 

> Cross-Site Scripting security vulnerability
> -------------------------------------------
>
>                 Key: STORM-408
>                 URL: https://issues.apache.org/jira/browse/STORM-408
>             Project: Apache Storm (Incubating)
>          Issue Type: Bug
>    Affects Versions: 0.9.0.1
>         Environment: Java
>            Reporter: Anand Krishnan
>              Labels: security
>
> There are Cross-Site Scripting security vulnerabilities in Apache Storm.
> The risk is that it is possible to steal or manipulate customer session and 
> cookies, which might be used to impersonate a legitimate user, allowing the 
> hacker to view or alter user records, and to perform transactions as that 
> user.
> The reason is that sanitation of hazardous characters was not performed 
> correctly on user input.



--
This message was sent by Atlassian JIRA
(v6.2#6252)

Reply via email to