|
|
Subscribe / Log in / New account

pagure: cross-site scripting

Package(s):pagure CVE #(s):CVE-2016-1000037
Created:August 23, 2016 Updated:August 24, 2016
Description:

From the Red Hat bug report:

It was found that Pagure served uploaded files from its attachment endpoint with content types that instructed the browser to parse HTML files, which could lead to Cross-Site Scripting attacks.

Alerts:
Fedora FEDORA-2016-40d5f1d3c2 pagure 2016-08-23

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds