Actions
Bug #16923
closed
JP
JP
Potential XSS via inline Firewall Log rule descriptions
Bug #16923:
Potential XSS via inline Firewall Log rule descriptions
Start date:
Due date:
% Done:
100%
Estimated time:
Plus Target Version:
26.07
Release Notes:
Default
Affected Version:
Affected Architecture:
Description
When firewall rule descriptions are enabled in the firewall log (either as a column or row), the rule labels/descriptions are printed to the user without encoding.
Files
JP Updated by Jim Pingle 2 months ago
- File 16923-2.8.1.patch 16923-2.8.1.patch added
- File 16923.patch 16923.patch added
- Status changed from Confirmed to Feedback
- % Done changed from 0 to 100
Fixed by commit 7c49f0bb23e2beac256dcf55c11810d7e5702734
CE 2.8.1 requires a different fix as the code has diverged significantly.
Patches attached.
GT Updated by Georgiy Tyutyunnik about 2 months ago
- Status changed from Feedback to Resolved
fixed in the latest dev
Tested on:
26.07-BETA (amd64)
built on Fri Jul 17 15:34:00 UTC 2026
FreeBSD 16.0-CURRENT
JP Updated by Jim Pingle about 1 month ago
- Private changed from Yes to No
Actions