Skip to content
Snippets Groups Projects
Verified Commit a14ee68f authored by Douwe Maan's avatar Douwe Maan Committed by Rémy Coutable
Browse files

Merge branch 'markdown-xss-fix-option-2.1' into 'security'

Fix for HackerOne XSS vulnerability in markdown

This is an updated blacklist patch to fix https://dev.gitlab.org/gitlab/gitlabhq/merge_requests/2007. No text is removed. Dangerous schemes/protocols and invalid URIs are left intact but not linked.

Fixes https://gitlab.com/gitlab-org/gitlab-ce/issues/23153



See merge request !2015

Signed-off-by: default avatarRémy Coutable <remy@rymai.me>
parent bf061d0a
No related branches found
No related tags found
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment