mirror of
https://github.com/zulip/zulip.git
synced 2026-06-27 21:01:32 +08:00
This fixes a cross-site scripting vulnerability in the upcoming Inline URL Previews feature found by Graham Bleaney and Ibrahim Mohamed using Pysa. This commit doesn't get a CVE because the bug was present in a code path introduced in the 2.1.x development branch, so it doesn't impact any Zulip release. Signed-off-by: Anders Kaseorg <anders@zulipchat.com> |
||
|---|---|---|
| .. | ||
| assets | ||
| audio | ||
| generated | ||
| html | ||
| images | ||
| js | ||
| shared | ||
| styles | ||
| templates | ||
| third | ||
| .gitignore | ||
| favicon.ico | ||