summaryrefslogtreecommitdiff
path: root/changelogs/unreleased/security-11-4-54377-label-milestone-name-xss.yml
diff options
context:
space:
mode:
authorKushal Pandya <kushal@gitlab.com>2018-12-20 12:11:46 +0000
committerKushal Pandya <kushal@gitlab.com>2018-12-20 12:11:46 +0000
commit28f0849e0f2a791296a3617e3f9343060adde63d (patch)
treeb039e80b43bc098130b59255fdb05a33094824e2 /changelogs/unreleased/security-11-4-54377-label-milestone-name-xss.yml
parentbb039bedb0c3dab6adb9cd407316eda22c963954 (diff)
downloadgitlab-ce-28f0849e0f2a791296a3617e3f9343060adde63d.tar.gz
Add changelog entry
Diffstat (limited to 'changelogs/unreleased/security-11-4-54377-label-milestone-name-xss.yml')
-rw-r--r--changelogs/unreleased/security-11-4-54377-label-milestone-name-xss.yml5
1 files changed, 5 insertions, 0 deletions
diff --git a/changelogs/unreleased/security-11-4-54377-label-milestone-name-xss.yml b/changelogs/unreleased/security-11-4-54377-label-milestone-name-xss.yml
new file mode 100644
index 00000000000..b20f9fd83cc
--- /dev/null
+++ b/changelogs/unreleased/security-11-4-54377-label-milestone-name-xss.yml
@@ -0,0 +1,5 @@
+---
+title: Escape label and milestone titles to prevent XSS in GFM autocomplete
+merge_request: 2742
+author:
+type: security