Changes between Initial Version and Version 6 of Ticket #30
- Timestamp:
- 12/02/11 15:32:45 (13 years ago)
Legend:
- Unmodified
- Added
- Removed
- Modified
-
Ticket #30
- Property Summary Security review - XSS/input validation → Security review
-
Ticket #30 – Description
initial v6 1 XSS/input validation: 1 2 Reading back on VegaDNS' history I poked into the CVE issues reported with VegaDNS 0.9.9.1 and 1.1.4. I realized the same message-reporting vulnerability would bite here. 3 4 Access scoping: 5 Check to make sure a user can't access any entity outside of their group tree