-
- Downloads
Merge branch 'security-11-4-54377-label-milestone-name-xss' into 'security-11-4'
[11.4] Escape label and milestone titles to prevent XSS in GFM autocomplete See merge request gitlab/gitlabhq!2742
No related branches found
No related tags found
Showing
- app/assets/javascripts/gfm_auto_complete.js 10 additions, 6 deletionsapp/assets/javascripts/gfm_auto_complete.js
- changelogs/unreleased/security-11-4-54377-label-milestone-name-xss.yml 5 additions, 0 deletions...released/security-11-4-54377-label-milestone-name-xss.yml
- spec/features/issues/gfm_autocomplete_spec.rb 41 additions, 0 deletionsspec/features/issues/gfm_autocomplete_spec.rb
Please register or sign in to comment