Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backport "Prevent HTML/XSS Injection in Scala Search" to LTS #21005

Merged
merged 1 commit into from
Jul 4, 2024

Conversation

WojciechMazur
Copy link
Contributor

Backports #19980 to the LTS branch.

PR submitted by the release tooling.
[skip ci]

This PR fixes the `_layouts/search.html` file to use `innerText` rather
than `innerHTML`. This will prevent the ability to inject HTML/XSS into
the code of the page.
[Cherry-picked 4554131]
Base automatically changed from lts-19914 to lts-3.3 July 4, 2024 10:02
@WojciechMazur
Copy link
Contributor Author

No regressions detected in the community build up to lts-19986.

Reference

@WojciechMazur WojciechMazur merged commit 29c9888 into lts-3.3 Jul 4, 2024
19 checks passed
@WojciechMazur WojciechMazur deleted the lts-19980 branch July 4, 2024 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants