Tim Abbott
f055a7d133
CVE-2018-9987: Fix XSS issue with muting notifications.
...
This fixes an XSS issue with Zulip's muting UI, where if a stream or
topic name contained malicious HTML containing JavaScript, and the
user did a muting interaction, the malicious JavaScript could run when
rendering the "you just muted a topic" notification.
We did an audit for similarly problematic use of `.html`, and found
none; for the next release we'll be merging a series of changes to our
linter to prevent future instances of this being added.
Thanks to Suhas Sunil Gaikwad for reporting this issue.
2018-04-10 13:05:27 -07:00
..
2017-10-19 16:10:14 -07:00
2017-10-18 10:22:18 -07:00
2017-10-11 20:39:28 -07:00
2017-08-28 17:20:13 -07:00
2017-08-28 17:20:13 -07:00
2017-09-26 14:00:51 -07:00
2017-10-12 14:03:36 -07:00
2017-09-28 16:16:16 -07:00
2017-10-17 22:05:56 -07:00
2017-06-15 10:08:31 -07:00
2017-07-25 14:02:12 -07:00
2017-09-25 12:31:07 -07:00
2017-10-08 15:48:44 -07:00
2017-08-01 15:38:17 -07:00
2017-06-27 14:06:59 -04:00
2017-09-19 19:07:30 -07:00
2017-10-06 12:36:59 -07:00
2017-10-17 16:06:13 -07:00
2017-09-06 08:53:39 -07:00
2017-07-24 10:47:16 -07:00
2017-07-24 10:47:16 -07:00
2017-10-20 13:07:40 -07:00
2017-10-11 17:44:03 -07:00
2017-10-12 14:03:36 -07:00
2017-10-05 15:51:06 -07:00
2017-09-29 21:10:03 +00:00
2017-10-18 10:22:18 -07:00
2017-09-26 13:58:54 -07:00
2017-06-19 06:53:25 -04:00
2017-10-24 13:19:24 -07:00
2017-07-27 14:16:57 -07:00
2017-10-18 10:22:18 -07:00
2017-06-15 12:16:27 -07:00
2017-10-05 19:05:27 +05:30
2017-09-15 04:14:52 -07:00
2017-06-22 11:07:30 -04:00
2017-10-06 12:36:59 -07:00
2017-08-05 16:47:11 -07:00
2017-09-10 00:40:03 -07:00
2017-10-12 10:42:06 -07:00
2017-09-29 11:14:34 -07:00
2017-10-12 18:08:32 -07:00
2017-10-23 11:02:30 -07:00
2017-08-01 22:38:22 -07:00
2017-08-04 13:31:26 -07:00
2017-10-23 11:02:30 -07:00
2017-10-11 15:57:11 -07:00
2017-08-27 09:34:24 -07:00
2017-08-01 08:58:56 -07:00
2017-10-18 10:22:18 -07:00
2018-04-10 13:05:27 -07:00
2017-06-27 14:06:59 -04:00
2017-10-17 22:05:56 -07:00
2017-10-03 11:28:28 -07:00
2017-10-23 21:29:42 -07:00
2017-10-06 12:36:59 -07:00
2017-10-24 15:59:51 -07:00
2017-08-22 09:37:17 -07:00
2017-07-21 11:38:25 -07:00
2017-10-24 15:59:51 -07:00
2017-10-12 10:42:06 -07:00
2017-10-09 11:31:21 -07:00
2017-09-14 07:20:52 -07:00
2017-10-11 20:39:28 -07:00
2017-10-18 21:55:43 -07:00
2017-08-22 09:37:17 -07:00
2017-10-06 12:36:59 -07:00
2017-08-22 12:50:54 -07:00
2017-10-06 12:36:59 -07:00
2017-10-06 12:36:59 -07:00
2017-10-17 22:05:56 -07:00
2017-08-27 19:11:43 -07:00
2017-10-11 20:39:28 -07:00
2017-10-04 14:45:08 -07:00
2017-09-06 13:44:02 -07:00
2017-09-06 09:35:16 -07:00
2017-07-21 13:29:27 -07:00
2017-07-27 14:16:57 -07:00
2017-09-30 09:11:18 -07:00
2017-09-29 17:58:41 -07:00
2017-09-27 18:46:19 -07:00
2017-09-26 22:54:20 -07:00
2017-10-23 13:57:11 -07:00
2017-09-27 17:50:22 -07:00
2017-07-27 14:16:57 -07:00
2017-07-18 12:03:16 -07:00
2017-09-06 18:49:54 -07:00
2017-10-11 16:17:36 -07:00
2017-10-08 12:31:12 -07:00
2017-10-18 11:45:07 -07:00
2017-10-23 22:44:27 -07:00
2017-09-08 11:20:36 -07:00
2017-08-16 18:03:44 -07:00
2017-09-15 00:22:59 -07:00
2017-10-23 22:56:14 -07:00
2017-09-24 11:58:48 -04:00
2017-06-26 19:33:25 -04:00
2017-09-06 07:01:43 -07:00
2017-08-14 13:03:57 -07:00
2017-08-08 17:07:09 -04:00
2017-08-17 09:01:49 -07:00
2017-10-18 10:22:18 -07:00
2017-10-20 10:08:17 -07:00
2017-10-09 15:13:33 -07:00
2017-09-29 11:14:34 -07:00
2017-09-26 13:42:14 -07:00
2017-09-26 13:42:14 -07:00
2017-09-26 13:42:14 -07:00
2017-09-26 13:42:14 -07:00
2017-10-18 21:55:43 -07:00
2017-09-16 03:01:51 -07:00
2017-10-17 22:03:33 -07:00
2017-08-15 10:40:02 -07:00
2017-08-17 23:30:41 -04:00
2017-09-22 10:20:19 -07:00
2017-08-22 23:48:55 -07:00
2017-08-16 16:23:41 -07:00
2017-07-04 13:54:33 -07:00