summaryrefslogtreecommitdiff
path: root/spec
Commit message (Expand)AuthorAgeFilesLines
* Merge branch 'security-54857-fix-templates-path-traversal-11-3' into 'securit...Cindy Pallares2018-12-053-1/+66
* Merge branch 'security-fix-uri-xss-applications-11-3' into 'security-11-3'Steve Azzopardi2018-11-263-1/+76
|\
| * Resolve reflected XSS in Ouath authorize windowJames Lopez2018-11-263-1/+76
* | [11.3] Fix CRLF issue in UrlValidatorFrancisco Javier López2018-11-263-34/+92
* | Merge branch 'security-11-3-fix-webhook-ssrf-ipv6' into 'security-11-3'Steve Azzopardi2018-11-261-9/+99
|\ \
| * | Fix SSRF in project integrationsFrancisco Javier López2018-11-121-9/+99
* | | [11.3] Fixed ability to comment on and edit/delete comments on locked or conf...Chantal Rollison2018-11-264-32/+155
| |/ |/|
* | Merge branch 'security-fix-pat-web-access-11-3' into 'security-11-3'Steve Azzopardi2018-11-2613-240/+429
|\ \
| * | Update code to use API scope on PAT authJames Lopez2018-11-2313-240/+429
* | | Merge branch 'security-11-3-xss-in-markdown-following-unrecognized-html-eleme...Steve Azzopardi2018-11-231-0/+12
|\ \ \
| * | | Sanitize output of SpacedLinkFilterBrett Walker2018-11-161-0/+12
| | |/ | |/|
* | | Merge branch 'security-mermaid-xss-11-3' into 'security-11-3'Steve Azzopardi2018-11-232-1/+13
|\ \ \
| * | | Add failing test for XSS in mermaid diagramsWinnie Hellmann2018-11-192-1/+13
| | |/ | |/|
* | | Merge branch 'security-bvl-exposure-in-commits-list-11-3' into 'security-11-3'Steve Azzopardi2018-11-231-2/+21
|\ \ \
| * | | Don't use fragment cache on commit pageBob Van Landuyt2018-11-191-2/+21
| |/ /
* | | Merge branch 'security-issue_51301-11-3' into 'security-11-3'Steve Azzopardi2018-11-232-6/+59
|\ \ \
| * | | Fix milestone promotion authorizationFelipe Artur2018-11-142-6/+59
| | |/ | |/|
* | | Merge branch 'security-2736-prometheus-ssrf-11-3' into 'security-11-3'Steve Azzopardi2018-11-232-2/+19
|\ \ \
| * | | No redirects in prometheus servicerpereira22018-11-142-2/+19
| |/ /
* | | Merge branch 'security-11-3-stored-xss-for-environments' into 'security-11-3'Steve Azzopardi2018-11-233-3/+39
|\ \ \
| * | | Validate URI scheme also for internal URIAlessio Caiazza2018-11-143-3/+39
| |/ /
* | | Merge branch 'security-private-group-11-3' into 'security-11-3'Steve Azzopardi2018-11-231-0/+10
|\ \ \ | |_|/ |/| |
| * | Fixed read name of private groupsChantal Rollison2018-11-071-0/+10
| |/
* | Merge branch 'sh-fix-issue-54189-11-3' into 'security-11-3'Steve Azzopardi2018-11-182-1/+30
|\ \
| * | Prevent templated services from being importedStan Hu2018-11-182-1/+30
| |/
* | Merge branch 'security-11-3-2717-xss-username-autocomplete' into 'security-11-3'Steve Azzopardi2018-11-181-6/+23
|\ \
| * | Fix user name autocomplete XSS when name contains HTMLKushal Pandya2018-11-121-6/+23
| |/
| * Merge branch 'sh-validate-wiki-attachments-11-3' into 'security-11-3'Thiago Presa2018-10-241-0/+10
| |\
| | * Validate Wiki attachments are valid temporary filesStan Hu2018-10-231-0/+10
| * | Merge branch 'security-11-3-2717-fix-issue-title-xss' into 'security-11-3'Jan Provaznik2018-10-241-0/+15
| |\ \
| | * | Add spec to test HTML escaping while rendering autocompleteKushal Pandya2018-10-191-0/+15
| * | | Merge branch 'security-redact-links-11-3' into 'security-11-3'Jan Provaznik2018-10-243-0/+207
| |\ \ \
| | * | | Redact unsubscribe links in issuable textsJan Provaznik2018-10-233-0/+207
| | | |/ | | |/|
| * | | Fix content caching for non auth usersJames Lopez2018-10-233-7/+56
| |/ /
| * | [11.3] Persist only SHA digest of PersonalAccessToken#tokenImre Farkas2018-10-235-11/+389
| * | Merge branch 'security-11-3-51527-xss-in-mr-source-branch' into 'security-11-3'Thiago Presa2018-10-231-0/+9
| |\ \
| | * | Fix XSS in MR source branch namePaul Slaughter2018-10-121-0/+9
| | |/
| * | Prevent SSRF attacks in HipChat integrationStan Hu2018-10-121-0/+18
| |/
| * Merge branch 'security-bw-confidential-titles-through-markdown-api-11-3' into...Bob Van Landuyt2018-10-041-0/+46
| |\
| | * post_process markdown redered by APIBrett Walker2018-09-291-0/+46
| * | Merge branch 'security-fix-leaking-private-project-namespace-11-3' into 'secu...Bob Van Landuyt2018-10-041-20/+47
| |\ \
| | * | Filter system notes with public and private cross referencesBrett Walker2018-10-021-20/+47
| | |/
| * | Merge branch 'security-osw-user-info-leak-discussions-11-3' into 'security-11-3'Bob Van Landuyt2018-10-042-0/+33
| |\ \
| | * | Filter user sensitive data from discussions JSONOswaldo Ferreira2018-10-012-0/+33
| | |/
| | * Merge branch 'security-fj-stored-xss-in-repository-imports-11-3' into 'securi...Bob Van Landuyt2018-09-252-0/+73
| | |\
| | | * Applied changesFrancisco Javier López2018-09-172-0/+73
| | * | Merge branch 'security-package-json-xss-11-3' into 'security-11-3'Bob Van Landuyt2018-09-251-4/+17
| | |\ \
| | | * | Fix xss vulnerability sourced from package.json's homepageMark Chao2018-09-191-4/+17
| | * | | Merge branch 'fix-events-finder-incomplete-11-3' into 'security-11-3'Bob Van Landuyt2018-09-242-0/+192
| | |\ \ \
| | | * | | Check snippet note event visibilityNick Thomas2018-09-211-0/+87