Uploaded image for project: 'Dev - Nexus Repo'
  1. Dev - Nexus Repo
  2. NEXUS-16470

Tree-view: user-supplied filter is concatenated with query without escaping/sanitizing

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Critical
    • Resolution: Fixed
    • Affects Version/s: 3.8.0, 3.7.1, 3.9.0
    • Fix Version/s: 3.10.0
    • Component/s: Tree View
    • Labels:
      None

      Description

      Open tree-view for any repository and type a single quote into the filter box. You'll get a parse exception because the generated query has an odd number of single quotes.

        Attachments

          Activity

            People

            Assignee:
            mbucher Michael Bucher
            Reporter:
            mcculls Stuart McCulloch
            Last Updated By:
            Peter Lynch
            Team:
            Nexus - Platform
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Date of First Response:

                tigCommentSecurity.panel-title