summaryrefslogtreecommitdiff
path: root/gitweb/gitweb.perl
diff options
context:
space:
mode:
authorLibravatar Junio C Hamano <gitster@pobox.com>2012-11-20 10:37:27 -0800
committerLibravatar Junio C Hamano <gitster@pobox.com>2012-11-20 10:37:27 -0800
commit79a09bba1cc919f5ea0992db358fb4b14ab2c226 (patch)
tree40b89ba60b8c8210030eb64e519f0abd1a8ce739 /gitweb/gitweb.perl
parentMerge branch 'rh/maint-gitweb-highlight-ext' (diff)
parentgitweb: escape html in rss title (diff)
downloadtgif-79a09bba1cc919f5ea0992db358fb4b14ab2c226.tar.xz
Merge branch 'jk/maint-gitweb-xss'
Fixes an XSS vulnerability in gitweb. * jk/maint-gitweb-xss: gitweb: escape html in rss title
Diffstat (limited to 'gitweb/gitweb.perl')
-rwxr-xr-xgitweb/gitweb.perl1
1 files changed, 1 insertions, 0 deletions
diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
index ce8cb4af16..e8812fa2b9 100755
--- a/gitweb/gitweb.perl
+++ b/gitweb/gitweb.perl
@@ -8054,6 +8054,7 @@ sub git_feed {
$feed_type = 'history';
}
$title .= " $feed_type";
+ $title = esc_html($title);
my $descr = git_get_project_description($project);
if (defined $descr) {
$descr = esc_html($descr);