Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixes #101: Add escape for CVE-2017-12097 #104

Merged
merged 1 commit into from
Jun 1, 2018

Conversation

breckenedge
Copy link
Contributor

Triggered by including HTML in the queues param which is then combined with an A tag in raw HTML via the url_path (alias u) helper. Fixed by adding a CGI escape to the helper.

https://nvd.nist.gov/vuln/detail/CVE-2017-12097

@andyatkinson
Copy link
Collaborator

delayed_job_web 1.4.2 was released, please update and reply back here if it's working ok.

@breckenedge
Copy link
Contributor Author

delayed_job_web 1.4.2 was released, please update and reply back here if it's working ok.

Thank you! It's deployed and working OK.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants