Uploaded image for project: 'OpenOLAT'
  1. OpenOLAT
  2. OO-4024

Bug in Batik breaks XSS validation

    XMLWordPrintable

    Details

    • Type: Task
    • Status: Closed (View Workflow)
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 12.5.22, 13.2.4
    • Component/s: None
    • Labels:
      None

      Description

      If a user enters in the rich text editor a background color with percent values like rgb(100%,10%,0), it get a red screen. this is critical for 2 reasons:

      • The user get a red screen
      • If such a value is written in a file or in the database, the output validation will produce a red screen every time an innocent user try to see the value.

        Attachments

          Activity

            People

            Assignee:
            srosse Stéphane Rossé
            Reporter:
            d.haag Daniel Haag
            Tester:
            Mandy Menzel
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:

                Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 1 hour, 5 minutes
                1h 5m