mirror of https://github.com/zulip/zulip.git
8459185970
This fixes a cross-site scripting vulnerability in the upcoming Inline URL Previews feature found by Graham Bleaney and Ibrahim Mohamed using Pysa. This commit doesn't get a CVE because the bug was present in a code path introduced in the 2.1.x development branch, so it doesn't impact any Zulip release. Signed-off-by: Anders Kaseorg <anders@zulipchat.com> |
||
---|---|---|
.. | ||
assets | ||
audio | ||
generated | ||
html | ||
images | ||
js | ||
shared | ||
styles | ||
templates | ||
third | ||
.gitignore | ||
favicon.ico |