Skip to content

Conversation

notriddle
Copy link
Contributor

@notriddle notriddle commented Jul 8, 2021

XSS vuln in Ammonia.

I don't know how to exploit it without allowing <iframe>, which it doesn't allow by default, but that's not an unreasonable thing for someone to do.

rust-ammonia/ammonia#142

@Shnatsel
Copy link
Member

Shnatsel commented Jul 8, 2021

I don't know how to exploit it without allowing <iframe>, which it doesn't allow by default, but that's not an unreasonable thing for someone to do.

Would it make sense to add this to the text of the advisory, to help users assess its impact?

@notriddle
Copy link
Contributor Author

Okay, I added a better version of that text to the doc.

@Shnatsel Shnatsel merged commit 3533e43 into rustsec:main Jul 8, 2021
@Shnatsel
Copy link
Member

Shnatsel commented Jul 8, 2021

Merged. Thanks for reporting!

@notriddle notriddle deleted the notriddle/ammonia-advisory-ns branch July 8, 2021 19:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants