http://hg.code.sf.net:8000/p/roundup/code/atom-log/tip/share/roundup/templates/responsive/html/help.html Mercurial Repository: p/roundup/code: share/roundup/templates/responsive/html/help.html history 2024-07-09T09:07:09-04:00 fix(security): fix CVE-2024-39124, CVE-2024-39124, and CVE-2024-39125 http://hg.code.sf.net:8000/p/roundup/code/#changeset-28aa76443f58bc1605a9933bb4ea4d599c97af5a John Rouillard rouilj@ieee.org 2024-07-09T09:07:09-04:00 2024-07-09T09:07:09-04:00
changeset 28aa76443f58
branch
bookmark
tag
user John Rouillard <rouilj@ieee.org>
description fix(security): fix CVE-2024-39124, CVE-2024-39124, and CVE-2024-39125

Directions for fixing:

* `CVE-2024-39124`_ - :ref:`classhelpers (_generic.help.html) are
vulnerable to an XSS attack. <CVE-2024-39124>` Requires fixing
tracker homes.
* `CVE-2024-39125`_ - :ref:`if Referer header is set to a script
tag, it will be executed. <CVE-2024-39125>` Fixed in release 2.4.0,
directions available for fixing in prior versions.
* `CVE-2024-39126`_ - :ref:`PDF, XML and SVG files downloaded from
an issue can contain embedded JavaScript which is
executed. <CVE-2024-39126>` Fixed in release 2.4.0, directions
available for fixing in prior versions.

prior to 2.4.0 release this weekend that fixes the last two CVE's.
files
First stab at responsive templates using bootstrap http://hg.code.sf.net:8000/p/roundup/code/#changeset-4545225c449d669cefaff888d5061e9d17dc3fac Pradip Caulagi caulagi@gmail.com 2012-12-14T00:35:51+05:30 2012-12-14T00:35:51+05:30
changeset 4545225c449d
branch
bookmark
tag
user Pradip Caulagi <caulagi@gmail.com>
description First stab at responsive templates using bootstrap
files