Skip to content
GitLab
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
  • Sign in
  • T TYPO3.CMS
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Locked Files
  • Issues 0
    • Issues 0
    • List
    • Boards
    • Service Desk
    • Milestones
    • Iterations
    • Requirements
  • Merge requests 8
    • Merge requests 8
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
    • Test Cases
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Infrastructure Registry
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Code review
    • Insights
    • Issue
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • accessibilityaccessibility
  • TYPO3.CMS
  • Repository
Switch branch/tag
  • TYPO3.CMS
  • ..
  • TypeScript
  • TypeScript
  • Main.ts
Find file BlameHistoryPermalink
  • Oliver Bartsch's avatar
    [SECURITY] Mitigate XSS in viewpage · 39c5a432
    Oliver Bartsch authored Jul 20, 2021 and Oliver Hader's avatar Oliver Hader committed Jul 20, 2021
    The `viewpage` module contains a preset selection, where
    users can select different browser viewports. Since the
    corresponding preset labels, configurable via TSconfig,
    had not been encoded properly, is was vulnerable to XSS.
    
    The issue is addressed by properly encoding the labels.
    
    Resolves: #93702
    Releases: master, 11.3, 10.4, 9.5
    Change-Id: Ia22c5ab4332816614dd07a93d7e739d9fc1d8bac
    Security-Bulletin: CORE-SA-2021-009
    Security-References: CVE-2021-32667
    Reviewed-on: https://review.typo3.org/c/Packages/TYPO3.CMS/+/69991
    
    
    Tested-by: Oliver Hader's avatarOliver Hader <oliver.hader@typo3.org>
    Reviewed-by: Oliver Hader's avatarOliver Hader <oliver.hader@typo3.org>
    39c5a432