Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-19676

TAP test description does not get escaped

    XMLWordPrintable

Details

    Description

      One of my tests outputs text that contains what looks like an HTML tag:

      ok 19 - msg is "defO01<<TRUNCATED>>"

      The Description column for this test on the TAP Extended Test Results page looks like this:

      - msg is "defO01<>"

      When I browse the source HTML for this section of the page, the text from the TAP output is definitely not being escaped. This could lead to cross-site scripting issues.

      Attachments

        Activity

          anjohnson Andrew Johnson created issue -
          kinow Bruno P. Kinoshita made changes -
          Field Original Value New Value
          Status Open [ 1 ] In Progress [ 3 ]
          kinow Bruno P. Kinoshita made changes -
          Attachment JENKINS-19676-001.png [ 30752 ]
          kinow Bruno P. Kinoshita made changes -
          Status In Progress [ 3 ] Open [ 1 ]
          scm_issue_link SCM/JIRA link daemon made changes -
          Resolution Fixed [ 1 ]
          Status Open [ 1 ] Resolved [ 5 ]
          kinow Bruno P. Kinoshita made changes -
          Status Resolved [ 5 ] Closed [ 6 ]
          rtyler R. Tyler Croy made changes -
          Workflow JNJira [ 151193 ] JNJira + In-Review [ 206965 ]

          People

            kinow Bruno P. Kinoshita
            anjohnson Andrew Johnson
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: