Skip to content
GitLab
    • Explore Projects Groups Topics Snippets
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • fusiondirectory fusiondirectory
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Issues 39
    • Issues 39
    • List
    • Boards
    • Service Desk
    • Milestones
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Terraform modules
  • Activity
  • Graph
  • Create a new issue
  • Commits
  • Issue Boards
Collapse sidebar
  • fusiondirectoryfusiondirectory
  • fusiondirectoryfusiondirectory
  • Issues
  • #3316
Something went wrong while setting issue due date.
Closed
Open
Issue created 10 years ago by bmortier@bmortierMaintainer
  • New related issue

  • New related issue

possible xss in login screen

Closed

possible xss in login screen

Hello,

there is a fix for an xss in the gosa code, mayber we are affected too

http://anonscm.debian.org/cgit/debian-edu/pkg-team/gosa.git/commit/?id=e8a1651380fee4de005750487e926c2971b86290

debian/patches: Add 0003_xss-vulnerability-on-login-screen.patch. Escape html entities to fix xss at the login screen. (Closes: #753388).

Cheers

(from redmine: issue id 3316, created on 2014-09-02, closed on 2014-09-22)

  • Changesets:
    • Revision 13ecbb25 by Côme Chilliet on 2014-09-15T12:35:52.000Z:
Fixes: #3316 possible xss in login screen
  • Revision 88e9c859 by Côme Chilliet on 2014-09-15T12:36:08.000Z:
Fixes: #3316 possible xss in login screen
  • Custom Fields:
    • Bug in version: 1.0.8.1
  • Uploads:
    • 0001-Fixes-3316-possible-xss-in-login-screen.patch

    Tasks

    0

    No tasks are currently assigned. Use tasks to break down this issue into smaller parts.

    Linked items
    0

    Link issues together to show that they're related. Learn more.

    Activity


    • bmortier
      bmortier @bmortier · 10 years ago
      Author Maintainer

      Hello,

      applied to 1.0.8.2-fixes and develop

      Cheers

      (from redmine: written on 2014-09-15)

      By bmortier on 2017-09-02T15:13:05 (imported from GitLab)

    • bmortier
      bmortier @bmortier · 10 years ago
      Author Maintainer

      Test to create an user with "

      bug

      " uid and it give an error. It is good.

      Selenium test is add too.

      Close issue

      (from redmine: written on 2014-09-22)

      By Jonathan Swaelens on 2017-09-02T15:13:05 (imported from GitLab)

    • bmortier closed 7 years ago

      closed

      By Jonathan Swaelens on 2017-09-02T15:13:06 (imported from GitLab)

    • bmortier added Security label 6 years ago

      added Security label

      By bmortier on 2018-10-09T17:00:21 (imported from GitLab)

    • bmortier added fusiondirectory-core label 6 years ago

      added fusiondirectory-core label

      By bmortier on 2018-10-09T17:00:27 (imported from GitLab)

    • bmortier mentioned in issue fusiondirectory-security/security#1 5 years ago

      mentioned in issue fusiondirectory-security/security#1

      By bmortier on 2020-04-14T16:17:18 (imported from GitLab)

    • bmortier removed Bugs label 4 years ago

      removed Bugs label

    • bmortier added FSA-0007 label 4 years ago

      added FSA-0007 label

    • bmortier added FSA-0006 label and removed FSA-0007 label 4 years ago

      added FSA-0006 label and removed FSA-0007 label

    Please register or sign in to reply
    Assignee
    bmortier's avatar
    bmortier
    Assign to
    Labels
    0
    None
    0
    None
      Assign labels
    • Manage project labels

    Milestone
    No milestone
    None
    Due date
    None
    None
    None
    Time tracking
    No estimate or time spent
    Confidentiality
    Not confidential
    Not confidential

    You are going to turn on confidentiality. Only project members with at least the Reporter role, the author, and assignees can view or be notified about this issue.

    Lock issue
    Unlocked
    0
    0 Participants
    Reference:

    Menu

    Explore Projects Groups Topics Snippets