Project

General

Profile

Actions

Bug #16923

closed
JP JP

Potential XSS via inline Firewall Log rule descriptions

Bug #16923: Potential XSS via inline Firewall Log rule descriptions

Added by Jim Pingle 2 months ago. Updated about 1 month ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Logging
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
26.07
Release Notes:
Default
Affected Version:
Affected Architecture:

Description

When firewall rule descriptions are enabled in the firewall log (either as a column or row), the rule labels/descriptions are printed to the user without encoding.


Files

16923-2.8.1.patch (863 Bytes) 16923-2.8.1.patch Patch for CE 2.8.1 Jim Pingle, 07/01/2026 06:38 PM
16923.patch (956 Bytes) 16923.patch Patch for Plus 26.03.1 Jim Pingle, 07/01/2026 06:38 PM

JP Updated by Jim Pingle 2 months ago Actions #1

Fixed by commit 7c49f0bb23e2beac256dcf55c11810d7e5702734

CE 2.8.1 requires a different fix as the code has diverged significantly.

Patches attached.

GT Updated by Georgiy Tyutyunnik about 2 months ago Actions #3

  • Status changed from Feedback to Resolved

fixed in the latest dev
Tested on:
26.07-BETA (amd64)
built on Fri Jul 17 15:34:00 UTC 2026
FreeBSD 16.0-CURRENT

JP Updated by Jim Pingle about 1 month ago Actions #4

  • Private changed from Yes to No
Actions

Also available in: Atom