[
https://issues.apache.org/jira/browse/YARN-1932?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13973485#comment-13973485
]
Hadoop QA commented on YARN-1932:
---------------------------------
{color:green}+1 overall{color}. Here are the results of testing the latest
attachment
http://issues.apache.org/jira/secure/attachment/12640708/YARN-1932.patch
against trunk revision .
{color:green}+1 @author{color}. The patch does not contain any @author
tags.
{color:green}+1 tests included{color}. The patch appears to include 1 new
or modified test files.
{color:green}+1 javac{color}. The applied patch does not increase the
total number of javac compiler warnings.
{color:green}+1 javadoc{color}. There were no new javadoc warning messages.
{color:green}+1 eclipse:eclipse{color}. The patch built with
eclipse:eclipse.
{color:green}+1 findbugs{color}. The patch does not introduce any new
Findbugs (version 1.3.9) warnings.
{color:green}+1 release audit{color}. The applied patch does not increase
the total number of release audit warnings.
{color:green}+1 core tests{color}. The patch passed unit tests in
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-common.
{color:green}+1 contrib tests{color}. The patch passed contrib unit tests.
Test results:
https://builds.apache.org/job/PreCommit-YARN-Build/3589//testReport/
Console output: https://builds.apache.org/job/PreCommit-YARN-Build/3589//console
This message is automatically generated.
> Javascript injection on the job status page
> -------------------------------------------
>
> Key: YARN-1932
> URL: https://issues.apache.org/jira/browse/YARN-1932
> Project: Hadoop YARN
> Issue Type: Bug
> Affects Versions: 3.0.0, 0.23.9, 2.5.0
> Reporter: Mit Desai
> Assignee: Mit Desai
> Priority: Blocker
> Attachments: YARN-1932.patch, YARN-1932.patch
>
>
> Scripts can be injected into the job status page as the diagnostics field is
> not sanitized. Whatever string you set there will show up to the jobs page as
> it is ... ie. if you put any script commands, they will be executed in the
> browser of the user who is opening the page.
> We need escaping the diagnostic string in order to not run the scripts.
--
This message was sent by Atlassian JIRA
(v6.2#6252)