-
- Downloads
Merge branch 'security-11-3-2717-xss-username-autocomplete' into 'security-11-3'
[11.3] Escape user fullname while rendering autocomplete template to prevent XSS See merge request gitlab/gitlabhq!2608
Showing
- app/assets/javascripts/gfm_auto_complete.js 11 additions, 4 deletionsapp/assets/javascripts/gfm_auto_complete.js
- changelogs/unreleased/security-11-3-2717-xss-username-autocomplete.yml 5 additions, 0 deletions...released/security-11-3-2717-xss-username-autocomplete.yml
- spec/features/issues/gfm_autocomplete_spec.rb 23 additions, 6 deletionsspec/features/issues/gfm_autocomplete_spec.rb
Please register or sign in to comment