Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Scaladoc js location synch more robust #4351

Merged
merged 1 commit into from Feb 20, 2015
Merged

Conversation

adriaanm
Copy link
Contributor

Fix the cross-site scripting vulnerability in Scaladoc’s JavaScript that was brought to our attention by @todesking -- thank you!

This vulnerability could be used to access sensitive information on sites hosted on the same domain as Scaladoc-generated documentation. We do recommend, as a general precaution, to host Scaladoc documentation on its own domain.

Tested on:

  • Mac: FF35/Safari 8/Chrome 41
  • Win: IE11

Tested on:
  - Mac: FF35/Safari 8/Chrome 41
  - Win: IE11
@scala-jenkins scala-jenkins added this to the 2.10.5 milestone Feb 20, 2015
adriaanm added a commit that referenced this pull request Feb 20, 2015
Scaladoc js location synch more robust
@adriaanm adriaanm merged commit 47be353 into scala:2.10.x Feb 20, 2015
@adriaanm adriaanm deleted the scaladoc-2.10 branch August 5, 2015 01:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants