manila-ui/manila_ui
Valeriy Ponomaryov fca19a1b0d Fix metadata_to_str function code injection vulnerability
It is possible to inject HTML/JavaScript code into shares table
member page setting metadata to shares and share types table admin page
setting extra specs. So, escape HTML-specific symbols in output
string of 'metadata_to_str' function to make it interpreted
as string and not as code.

Change-Id: Ied567e06d91941e9aaac7d3117e03cd1770fb75e
Security-Fix
Closes-Bug: #1597738
2016-09-28 14:53:11 +03:00
..
api Read list of AZs using manila's API instead of nova's 2016-09-12 14:54:52 +03:00
dashboards Fix metadata_to_str function code injection vulnerability 2016-09-28 14:53:11 +03:00
enabled Add Share Migration support 2016-09-01 10:57:55 -03:00
locale Imported Translations from Zanata 2016-09-14 08:17:34 +00:00
tests Fix metadata_to_str function code injection vulnerability 2016-09-28 14:53:11 +03:00
utils Incoporate get_item filter 2015-04-09 16:34:30 -07:00
__init__.py Fix pep8 violations 2015-04-09 16:34:30 -07:00
exceptions.py Register Manilaclient exceptions in Horizon 2016-05-10 13:26:31 +03:00