summaryrefslogtreecommitdiff
path: root/docker
diff options
context:
space:
mode:
authorKerri Miller <kerrizor@kerrizor.com>2019-05-20 13:24:22 -0700
committerKerri Miller <kerrizor@kerrizor.com>2019-05-24 12:33:24 -0700
commita76fdcb7a30c6244ffb11a2e672e16d1e5b413b2 (patch)
tree2df0435eaf290a601f8eb91346a4bed2d1153893 /docker
parenta600c0a78d7f9660d8f37f0f6fc98b61bdc275fb (diff)
downloadgitlab-ce-a76fdcb7a30c6244ffb11a2e672e16d1e5b413b2.tar.gz
Reject slug+uri concat if slug is deemed unsafe
First reported: https://gitlab.com/gitlab-org/gitlab-ce/issues/60143 When the page slug is "javascript:" and we attempt to link to a relative path (using `.` or `..`) the code will concatenate the slug and the uri. This MR adds a guard to that concat step that will return `nil` if the incoming slug matches against any of the "unsafe" slug regexes; currently this is only for the slug "javascript:" but can be extended if needed. Manually tested against a non-exhaustive list from OWASP of common javascript XSS exploits that have to to with mangling the "javascript:" method, and all are caught by this change or by existing code that ingests the user-specified slug.
Diffstat (limited to 'docker')
0 files changed, 0 insertions, 0 deletions