Project

General

Profile

Actions

Bug #9888

closed

ACME output sent to browser without encoding

Added by Jim Pingle over 4 years ago. Updated about 4 years ago.

Status:
Resolved
Priority:
High
Assignee:
Category:
ACME
Target version:
-
Start date:
11/08/2019
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Affected Version:
All
Affected Plus Version:
Affected Architecture:
All

Description

ACME issue/renew output is sent directly to the browser without encoding. In some cases, user input may be included in that output, leading to a potential XSS. Notably, the RootFolder parameter for the webroot local folder method is affected.

Actions #1

Updated by Jim Pingle over 4 years ago

  • Status changed from New to Feedback
Actions #2

Updated by Jim Pingle over 4 years ago

  • Private changed from Yes to No
Actions #3

Updated by Jim Pingle about 4 years ago

  • Status changed from Feedback to Resolved
  • % Done changed from 0 to 100

Fixed months ago, no additional feedback.

Actions

Also available in: Atom PDF