summaryrefslogtreecommitdiff
path: root/doc/recentchanges/change_0ea5f43790fe2ce3cc40e9513191e72c67a1ee51._change
blob: 99f032a4c593c0a4f0484621b02492e960e53b81 (plain)
  1. [[!meta author="""joey"""]]
  2. [[!meta authorurl="""http://ikiwiki.info/ikiwiki.cgi?page=users%2Fjoey&do=goto"""]]
  3. [[!meta title="""change to security on ikiwiki"""]]
  4. [[!meta permalink="http://ikiwiki.info/recentchanges/#change-0ea5f43790fe2ce3cc40e9513191e72c67a1ee51"]]
  5. <div id="change-0ea5f43790fe2ce3cc40e9513191e72c67a1ee51" class="metadata">
  6. <span class="desc"><br />Changed pages:</span>
  7. <span class="pagelinks">
  8. <a href="http://git.ikiwiki.info/?p=ikiwiki;a=blobdiff;f=doc/security.mdwn;h=33b199247dbf541362097124a984ceba6d93658e;hp=34a0052397fa857552051fc7e06cef84a1ccab01;hb=0ea5f43790fe2ce3cc40e9513191e72c67a1ee51;hpb=d5056fb61e8332fea658363e931ec28a35681ffe" title="diff" rel="nofollow">[[diff|wikiicons/diff.png]]</a><a href="http://ikiwiki.info/ikiwiki.cgi?page=security&amp;do=goto" rel="nofollow">security</a>
  9. </span>
  10. <span class="desc"><br />Changed by:</span>
  11. <span class="committer">
  12. <a href="http://ikiwiki.info/ikiwiki.cgi?page=users%2Fjoey&amp;do=goto" rel="nofollow">joey</a>
  13. </span>
  14. <span class="desc"><br />Commit type:</span>
  15. <span class="committype">git</span>
  16. <span class="desc"><br />Date:</span>
  17. <span class="changedate"><span class="relativedate" title="Fri, 12 Nov 2010 00:24:52 -0400">00:24:52 11/12/10</span></span>
  18. <span class="desc"><br /></span>
  19. </div>
  20. <span class="revert">
  21. <a href="http://ikiwiki.info/ikiwiki.cgi?rev=0ea5f43790fe2ce3cc40e9513191e72c67a1ee51&amp;do=revert" title="revert" rel="nofollow">[[revert|wikiicons/revert.png]]</a>
  22. </span>
  23. <div class="changelog">
  24. security issue<br />
  25. </div>
  26. <div class="diff">
  27. <pre>
  28. diff --git a/doc/security.mdwn b/doc/security.mdwn
  29. index 34a0052..33b1992 100644
  30. --- a/doc/security.mdwn
  31. +++ b/doc/security.mdwn
  32. @@ -440,3 +440,16 @@ with the release of ikiwiki 3.20100312.
  33. A fix was also backported to Debian etch, as version 2.53.5. I recommend
  34. upgrading to one of these versions if your wiki can be edited by third
  35. parties.
  36. +
  37. +## javascript insertation via insufficient htmlscrubbing of comments
  38. +
  39. +Kevin Riggle noticed that it was not possible to configure
  40. +`htmlscrubber_skip` to scrub comments while leaving unscubbed the text
  41. +of eg, blog posts. Confusingly, setting it to &quot;* and !comment(*)&quot; did not
  42. +scrub comments.
  43. +
  44. +Additionally, it was discovered that comments&#39; html was never scrubbed during
  45. +preview or moderation of comments.
  46. +
  47. +These problems were discovered on 12 November 2010 and fixed the same
  48. +hour with the release of ikiwiki 3.20101112.
  49. </pre>
  50. </div>
  51. <!-- 0ea5f43790fe2ce3cc40e9513191e72c67a1ee51 -->