Cross-Site-Scripting (XSS) Vulnarability: Github Titles rendered unescaped to build description

XMLWordPrintable

    • Type: Bug
    • Resolution: Won't Fix
    • Priority: Major
    • Component/s: ghprb-plugin
    • None

      When having a pull request title which contains quotes the title is put into the build description unescaped which actually allows XSS (e. g. execute a task in the name of a different user).

      At first glance it only corrupts the output:

            Assignee:
            Honza Brázdil
            Reporter:
            Mark Michaelis
            Votes:
            2 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: