summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKushal Pandya <kushal@gitlab.com>2018-12-20 12:07:04 +0000
committerKushal Pandya <kushal@gitlab.com>2018-12-20 12:07:04 +0000
commit597e22c4049b574436cb2258387137b559ad5f9b (patch)
treede0493b9fff457dbbf69c0092eee38ad5921c047
parent5f03d26a194c25abef20b94c175ac4f587e821a2 (diff)
downloadgitlab-ce-597e22c4049b574436cb2258387137b559ad5f9b.tar.gz
Add changelog entry
-rw-r--r--changelogs/unreleased/security-54377-label-milestone-name-xss.yml5
1 files changed, 5 insertions, 0 deletions
diff --git a/changelogs/unreleased/security-54377-label-milestone-name-xss.yml b/changelogs/unreleased/security-54377-label-milestone-name-xss.yml
new file mode 100644
index 00000000000..76589b2eb4f
--- /dev/null
+++ b/changelogs/unreleased/security-54377-label-milestone-name-xss.yml
@@ -0,0 +1,5 @@
+---
+title: Escape label and milestone titles to prevent XSS in GFM autocomplete
+merge_request: 2693
+author:
+type: security