| Summary: | "Referer" http header set from request.js script is detected as XSS vulnerability | ||
|---|---|---|---|
| Product: | [RT] RAP | Reporter: | Paul-Antoine Bourgeois <paul-antoine.bourgeois> |
| Component: | RWT | Assignee: | Project Inbox <rap-inbox> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | P3 | CC: | rsternberg |
| Version: | 2.3 | ||
| Target Milestone: | 3.1 M4 | ||
| Hardware: | PC | ||
| OS: | Windows 7 | ||
| See Also: | https://git.eclipse.org/r/#/c/60686/ | ||
| Whiteboard: | sr302 | ||
|
Description
Paul-Antoine Bourgeois
I agree that it's a legacy should be removed. The referrer header doesn't make sense for background requests anyway as they're not part of a "navigation". Fixed with change https://git.eclipse.org/r/#/c/60686/ Backported to 3.0-maintenance branch with change https://git.eclipse.org/r/#/c/64970/ |