Skip to content

Flash Security Risk #794

Description

@gitblit

Originally reported on Google Code with ID 498

Description:
    allowScriptAccess=”always” for a flash object is dangereous because it can allow a
cross domain privilege escalation or script injection.
Expected Output:
    The value of the flash object's allowScriptAccess attribute should be sameDomain.
Environment:
    Gitblit Version 1.6.0 running on rhel 6 / tomcat 7 / apache httpd 2.2 with proxy ajp

Reported by 1988porsche944 on 2014-09-05 13:46:37

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions