Possible XSS in Alarm Filter Favorites

Description

If the search query includes an apostrophe in the description field, then the label is shown incorrectly on the "Alarm Filter Favorites" tab.

I haven't tested enough to see if this is exploitable for XSS, or if it's just a rendering bug.

Acceptance / Success Criteria

None

Attachments

2

Lucidchart Diagrams

Activity

Show:

Markus von Rüden June 13, 2017 at 6:09 AM

The favorite tooltip was not escaped properly. PR: https://github.com/OpenNMS/opennms/pull/1539

Fixed

Details

Assignee

Reporter

Components

Sprint

Affects versions

Priority

PagerDuty

Created June 12, 2017 at 3:42 PM
Updated June 20, 2017 at 10:16 PM
Resolved June 20, 2017 at 6:17 PM