Skip to content

Fixed code injection vulnerability#1

Open
chrischen wants to merge 12 commits intoradiodan:masterfrom
chrischen:master
Open

Fixed code injection vulnerability#1
chrischen wants to merge 12 commits intoradiodan:masterfrom
chrischen:master

Conversation

@chrischen
Copy link

@chrischen chrischen commented Jul 9, 2016

SSID names aren't escaped creating a HTML/JS injection vulnerability and also preventing SSID names with quotes from being POSTed correctly.

gaudi and others added 12 commits March 15, 2016 13:30
Using this tag avoids issues with non-existent device images. This can
happen if a new devices gets support in resin and at the time node
version has advanced, so old docker images don't exist.

Fixes balena-os#38

Signed-off-by: Petros Angelatos <petrosagg@gmail.com>
Use the more generic 0.10 tag on the Dockerfile
Also fixes bug preventing quotes in SSID name.
* origin/master:
  Use connman-simplified as it works with newer versions of node e.g. v5
  Prepend iptables rules rather than append

Conflicts:
	package.json
@chrischen chrischen changed the title Fixed XSS vulnerability Fixed code injection vulnerability Jul 9, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants