sourceware.org Bugzilla seems run scripts in HTML

Florian Weimer fweimer@redhat.com
Sun Nov 12 17:16:00 GMT 2017


Hi,

as can be seen with this bug report:

   https://sourceware.org/bugzilla/show_bug.cgi?id=22422

Javascript in HTML attachments appears to be served in such a way that 
is run by browsers.  It is probably best not to visit that attachment 
while being logged in, in case that Javascript code tries to steal 
cookies etc.

Would it be possible to fix this?

Thanks,
Florian



More information about the Overseers mailing list