[jira] [Updated] (AMBARI-25439) XSS vulnerability for repo check hint

2022-11-17 Thread Zhiguo Wu (Jira)


 [ 
https://issues.apache.org/jira/browse/AMBARI-25439?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Zhiguo Wu updated AMBARI-25439:
---
Fix Version/s: 2.8.0
   Resolution: Fixed
   Status: Resolved  (was: Patch Available)

> XSS vulnerability for repo check hint
> -
>
> Key: AMBARI-25439
> URL: https://issues.apache.org/jira/browse/AMBARI-25439
> Project: Ambari
>  Issue Type: Task
>  Components: ambari-web
>Affects Versions: 2.7.5
>Reporter: Antonenko Alexander
>Assignee: Antonenko Alexander
>Priority: Critical
>  Labels: pull-request-available
> Fix For: 2.8.0, 2.7.5
>
>  Time Spent: 1h 20m
>  Remaining Estimate: 0h
>
> For now UI parses repo error hint as html. It is potential XSS vulnerability.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

-
To unsubscribe, e-mail: issues-unsubscr...@ambari.apache.org
For additional commands, e-mail: issues-h...@ambari.apache.org



[jira] [Updated] (AMBARI-25439) XSS vulnerability for repo check hint

2019-12-03 Thread ASF GitHub Bot (Jira)


 [ 
https://issues.apache.org/jira/browse/AMBARI-25439?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

ASF GitHub Bot updated AMBARI-25439:

Labels: pull-request-available  (was: )

> XSS vulnerability for repo check hint
> -
>
> Key: AMBARI-25439
> URL: https://issues.apache.org/jira/browse/AMBARI-25439
> Project: Ambari
>  Issue Type: Task
>  Components: ambari-web
>Affects Versions: 2.7.5
>Reporter: Antonenko Alexander
>Assignee: Antonenko Alexander
>Priority: Critical
>  Labels: pull-request-available
> Fix For: 2.7.5
>
>
> For now UI parses repo error hint as html. It is potential XSS vulnerability.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Updated] (AMBARI-25439) XSS vulnerability for repo check hint

2019-12-03 Thread Antonenko Alexander (Jira)


 [ 
https://issues.apache.org/jira/browse/AMBARI-25439?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Antonenko Alexander updated AMBARI-25439:
-
Status: Patch Available  (was: Open)

> XSS vulnerability for repo check hint
> -
>
> Key: AMBARI-25439
> URL: https://issues.apache.org/jira/browse/AMBARI-25439
> Project: Ambari
>  Issue Type: Task
>  Components: ambari-web
>Affects Versions: 2.7.5
>Reporter: Antonenko Alexander
>Assignee: Antonenko Alexander
>Priority: Critical
>  Labels: pull-request-available
> Fix For: 2.7.5
>
>  Time Spent: 10m
>  Remaining Estimate: 0h
>
> For now UI parses repo error hint as html. It is potential XSS vulnerability.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)