[ 
https://issues.apache.org/jira/browse/SLING-13313?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Carsten Ziegeler resolved SLING-13313.
--------------------------------------
    Resolution: Fixed

Improved with 
https://github.com/apache/sling-org-apache-sling-xss/commit/f73c46bbd1cae73db13d8e4581d9f1b8d9300b9f

> Improve javascript scheme detection in XSSAPI.getValidHref()
> ------------------------------------------------------------
>
>                 Key: SLING-13313
>                 URL: https://issues.apache.org/jira/browse/SLING-13313
>             Project: Sling
>          Issue Type: Improvement
>          Components: XSS Protection API
>    Affects Versions: XSS Protection API 2.4.10
>            Reporter: Carsten Ziegeler
>            Assignee: Carsten Ziegeler
>            Priority: Major
>             Fix For: XSS Protection API 2.4.12
>
>
> We can improve the scheme detection for javascript href to also account for 
> whitespace and similar characters which are ignored by browser



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to